×

Inferring file and website reputations by belief propagation leveraging machine reputation

  • US 8,341,745 B1
  • Filed: 02/22/2010
  • Issued: 12/25/2012
  • Est. Priority Date: 02/22/2010
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method for detecting malicious computer files, comprising:

  • generating a graph comprising nodes representing a plurality of clients and computer files residing thereon, wherein distinct clients and distinct computer files are represented by distinct nodes in the graph, wherein a node representing a client is connected to nodes representing computer files residing on that client through edges;

    determining priors for nodes in the graph and edge potentials for edges in the graph based on domain knowledge, wherein a prior for a node representing a client comprises an assessment of a likelihood of the client getting infected by malware based on the domain knowledge, a prior for a node representing a computer file comprises an assessment of a likelihood of the computer file being malware based on the domain knowledge, and an edge potential reflects a relationship between nodes connected by an associated edge based on the domain knowledge;

    iteratively propagating a probability of a computer file being legitimate among the nodes by transmitting messages along the edges in the graph, wherein a message transmitted by a node is generated based on a prior of the node and messages received by the node during any previous iterations; and

    determining whether a computer file is classified as malicious based on a probability associated with a corresponding node in the graph.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×