×

Malware detection via reputation system

  • US 8,719,939 B2
  • Filed: 01/26/2010
  • Issued: 05/06/2014
  • Est. Priority Date: 12/31/2009
  • Status: Active Grant
First Claim
Patent Images

1. A method of filtering digital electronic content, comprising:

  • accessing a digital file;

    extracting a plurality of high level features from the digital file;

    evaluating the plurality of high level features using a classifier on a first computer system to make an initial determination of whether the digital file is benign or malicious, the classifier on the first computer system using a first classification model;

    sending a hash of the digital file over a network to a reputation server computerized system for the reputation server to make a secondary determination of whether the digital file is benign or malicious, the secondary determination using a second classification model, wherein the reputation server tracks one or more characteristics of the hash of the digital file, the one or more characteristics comprising query volume per hash, time since first appearance of the hash, number of clients querying the hash, and distribution of clients querying the hash; and

    receiving at the first computer system from the reputation server an indication of the secondary determination, wherein the secondary determination is made after the initial determination, wherein the first classification model has a higher false positive rate than the second classification model.

View all claims
  • 10 Assignments
Timeline View
Assignment View
    ×
    ×