×

Apparatus method and medium for detecting payload anomaly using N-gram distribution of normal data

  • US 9,276,950 B2
  • Filed: 01/02/2014
  • Issued: 03/01/2016
  • Est. Priority Date: 11/12/2003
  • Status: Active Grant
First Claim
Patent Images

1. A method for verifying a file type, the method comprising:

  • receiving, using a hardware processor, a file identified as corresponding to a first file type from a first source;

    generating a byte value statistical distribution of the data included in the file received from the first source;

    selecting a model byte value statistical distribution representative of the first file type from model byte value statistical distributions representative of a plurality of file types;

    determining a distance metric between the byte value statistical distribution of the data included in the file and the selected model byte value statistical distribution; and

    verifying that a file type of the received file is the first file type based on a comparison of the distance metric to a distance metric threshold indicating that the file type of received file is the first file type.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×