The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Oct. 28, 2014

Filed:

Dec. 28, 2011
Applicants:

Gregory Sinclair, Concord, NC (US);

Ryan Olson, New York, NY (US);

Robert Falcone, North Attleborough, MA (US);

Inventors:

Gregory Sinclair, Concord, NC (US);

Ryan Olson, New York, NY (US);

Robert Falcone, North Attleborough, MA (US);

Assignee:

Verisign, Inc., Reston, VA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 7/00 (2006.01); G06F 17/30 (2006.01); H04L 29/06 (2006.01); G06F 21/56 (2013.01); G06Q 10/10 (2012.01); H04L 12/58 (2006.01);
U.S. Cl.
CPC ...
G06F 17/30705 (2013.01); H04L 63/1416 (2013.01); G06F 17/30997 (2013.01); G06F 21/564 (2013.01); G06F 21/565 (2013.01); G06Q 10/10 (2013.01); G06F 17/30707 (2013.01); G06F 17/30696 (2013.01); H04L 51/12 (2013.01);
Abstract

Systems and methods are disclosed for identifying associations between binary samples, such as e-mail files and their attachments or a document and an executable program associated with the document. In one implementation, the method includes receiving a plurality of binary samples, and extracting metadata from the plurality of binary samples. The metadata for a binary sample from the plurality of binary samples includes a set of attributes of the binary sample. The method further includes identifying a set of associations between the plurality of binary samples based on the extracted metadata. Each association is characterized by at least one attribute the associated binary samples have in common, and each association has a confidence level indicative of a strength of the association. The method also includes identifying associations with a confidence level that exceeds a predefined threshold.


Find Patent Forward Citations

Loading…