Invention Grant
- Patent Title: Mitigating false positives in malware detection
- Patent Title (中): 减轻恶意软件检测中的误报
-
Application No.: US12684719Application Date: 2010-01-08
-
Publication No.: US08719935B2Publication Date: 2014-05-06
- Inventor: Alexey A. Polyakov , Ravi Bikkula
- Applicant: Alexey A. Polyakov , Ravi Bikkula
- Applicant Address: US WA Redmond
- Assignee: Microsoft Corporation
- Current Assignee: Microsoft Corporation
- Current Assignee Address: US WA Redmond
- Agent Henry Gabryjelski; Kate Drakos; Micky Minhas
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/56

Abstract:
An anti-malware system that reduces the likelihood of detecting a false positive. The system is applied in an enterprise network in which a server receives reports of suspected malware from multiple hosts. Files on hosts suspected of containing malware are compared to control versions of those files. A match between a suspected file and a control version is used as an indication that the malware report is a false positive. Such an indication may be used in conjunction with other information, such as whether other hosts similarly report suspect files that match control versions or whether the malware report is generated by a recently changed component of the anti-malware system.
Public/Granted literature
- US20110173698A1 MITIGATING FALSE POSITIVES IN MALWARE DETECTION Public/Granted day:2011-07-14
Information query