Invention Grant
- Patent Title: Systems and methods for determining whether malicious files are targeted
-
Application No.: US15268260Application Date: 2016-09-16
-
Publication No.: US10216933B1Publication Date: 2019-02-26
- Inventor: Ryan Ross Curtin
- Applicant: Symantec Corporation
- Applicant Address: US CA Mountain View
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Mountain View
- Agency: FisherBroyles, LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/55 ; G06F21/56 ; G06F17/30 ; G06N99/00 ; G06F11/30

Abstract:
The disclosed computer-implemented method for determining whether malicious files are targeted may include (i) applying, to a malware detection structure, a plurality of sample data points, each sample data point corresponding to at least one of a malicious file known to be targeted and a malicious file known to be non-targeted, (ii) identifying one or more boundaries of the sample data points within the malware detection structure, (iii) determining, after identifying the sample boundaries, that a new data point falls outside of the boundaries, and (iv) classifying a malicious file associated with the new data point as non-targeted in response to determining that the new data point falls outside of the sample boundaries. Various other methods, systems, and computer-readable media are also disclosed.
Information query