×

Modeling goodware characteristics to reduce false positive malware signatures

  • US 8,028,338 B1
  • Filed: 09/30/2008
  • Issued: 09/27/2011
  • Est. Priority Date: 09/30/2008
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method of generating a model that specifies a likelihood of observing a characteristic in a set of goodware entities, the method comprising:

  • using a computer to perform steps comprising;

    determining a set of likelihood values associated with a set of characteristics associated with the set of goodware entities, each likelihood value specifying a likelihood of observing a characteristic of the set of characteristics in the set of goodware entities, wherein determining the set of likelihood values comprises identifying a set of enumeration values indicating numbers of times characteristics of the set of characteristics are observed in the set of goodware entities, and the likelihood values are based on the set of enumeration values;

    storing the set of characteristics in association with the set of likelihood values as a model;

    generating a set of relative information gain values associated with the characteristics of the set of characteristics, wherein a relative information gain value describes an amount of information an associated characteristic adds to the model;

    removing one or more characteristics from the model responsive to the relative information gain values associated with the one or more characteristics to produce a revised model; and

    storing the revised model.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×