The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Aug. 05, 2014

Filed:

Jun. 17, 2011
Applicants:

Jack W. Stokes, North Bend, WA (US);

Nikos Karampatziakis, Ithaca, NY (US);

John C. Platt, Bellevue, WA (US);

Anil Francis Thomas, Redmond, WA (US);

Adrian M. Marinescu, Sammamish, WA (US);

Inventors:

Jack W. Stokes, North Bend, WA (US);

Nikos Karampatziakis, Ithaca, NY (US);

John C. Platt, Bellevue, WA (US);

Anil Francis Thomas, Redmond, WA (US);

Adrian M. Marinescu, Sammamish, WA (US);

Assignee:

Microsoft Corporation, Redmond, WA (US);

Attorneys:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 21/56 (2013.01); G06K 9/62 (2006.01);
U.S. Cl.
CPC ...
G06K 9/62 (2013.01); G06K 9/6224 (2013.01); G06F 21/56 (2013.01); Y10S 707/952 (2013.01);
Abstract

A reliable automated malware classification approach with substantially low false positive rates is provided. Graph-based local and/or global file relationships are used to improve malware classification along with a feature selection algorithm. File relationships such as containing, creating, copying, downloading, modifying, etc. are used to assign malware probabilities and simultaneously reduce the false positive and false negative rates on executable files.


Find Patent Forward Citations

Loading…