Invention Grant
- Patent Title: System and method for evaluating malware detection rules
- Patent Title (中): 用于评估恶意软件检测规则的系统和方法
-
Application No.: US14288043Application Date: 2014-05-27
-
Publication No.: US09171155B2Publication Date: 2015-10-27
- Inventor: Alexey M. Romanenko , Ilya O. Tolstikhin , Sergey V. Prokudin
- Applicant: Kaspersky Lab ZAO
- Applicant Address: RU Moscow
- Assignee: KASPERSKY LAB ZAO
- Current Assignee: KASPERSKY LAB ZAO
- Current Assignee Address: RU Moscow
- Agency: Patterson Thuente Pedersen, P.A.
- Priority: RU2013143770 20130930
- Main IPC: G06F12/14
- IPC: G06F12/14 ; G06F21/56 ; G06F21/55 ; H04L29/06 ; G06F21/57

Abstract:
A malware detection rule is evaluated for effectiveness and accuracy. The detection rule defines criteria for distinguishing files having a characteristic of interest from other files lacking that characteristic, for instance, malicious files vs. benign files. The detection rule is applied to a set of unknown files. This produces a result set that contains files detected from among the set of unknown files as having the at least one characteristic of interest. Each file from the result set is compared to at least one file from a set of known files having the characteristic to produce a first measure of similarity, and to at least one file from a set of known files lacking the characteristic to produce a second measure of similarity. In response to the first measure of similarity exceeding a first similarity threshold, the detection rule is deemed effective. In response to the second measure of similarity exceeding a second similarity threshold, the detection rule is deemed inaccurate.
Public/Granted literature
- US20150096027A1 SYSTEM AND METHOD FOR EVALUATING MALWARE DETECTION RULES Public/Granted day:2015-04-02
Information query