Invention Grant
- Patent Title: Identifying suspected malware files and sites based on presence in known malicious environment
-
Application No.: US14283089Application Date: 2014-05-20
-
Publication No.: US10282544B2Publication Date: 2019-05-07
- Inventor: Tomer Brand , Dan Michelson
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Agency: Klarquist Sparkman, LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/56

Abstract:
Disclosed herein is a system and method for identifying potential sources of malicious activity as well as identifying potentially malicious files that originated from suspected malicious sources. Using an anchor event and telemetry data from devices known to have been infected by malicious activity similar events in the telemetry data between two devices can be identified. These satellite events are then used to identify other files that may have been deposited by the satellite event such that those files can be highlighted to a malware researcher. Additionally, the malware protection may be updated based on this analysis to label an associated site with the satellite event as a malicious site such that the site may be blocked or quarantined.
Public/Granted literature
- US20150341372A1 IDENTIFYING SUSPECTED MALWARE FILES AND SITES BASED ON PRESENCE IN KNOWN MALICIOUS ENVIRONMENT Public/Granted day:2015-11-26
Information query