×

Lineage-based reputation system

  • US 8,510,836 B1
  • Filed: 07/06/2010
  • Issued: 08/13/2013
  • Est. Priority Date: 07/06/2010
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method of determining a reputation score for a file, the method comprising:

  • using a computer to performs steps comprising;

    receiving a plurality of lineage reports from a plurality of clients, a lineage report specifying a lineage relationship for a file created at a client, the lineage report identifying a parent file and a child file created by the parent file at the client;

    generating a plurality of lineage scores for the file using a plurality of lineage metrics based on the plurality of lineage reports;

    aggregating the plurality of lineage scores for the file to produce an aggregated lineage score for the file, the aggregating comprising computing a proportion indicating how often the file is created by malware; and

    generating a reputation score for the file based at least in part on the aggregated lineage score, the reputation score indicating a likelihood that the file is malware.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×