Invention Grant
US09177142B2 Identification of electronic documents that are likely to contain embedded malware 有权
识别可能包含嵌入式恶意软件的电子文档

Identification of electronic documents that are likely to contain embedded malware
Abstract:
The present invention provides a method for determining the likelihood that an electronic document contains embedded malware. After parsing or sequencing an electronic document, the metadata structures that make up the document are analyzed. A number of pre-established rules are then applied with respect to certain metadata structures that are indicative of embedded malware. The application of these rules results in the generation of a score for the electronic document being tested for embedded malware. The score is then compared to a threshold value, where the threshold value was previously generated based on a statistical model relating to electronic documents having the same format as the document being tested. The result of the comparison can then be used to determine whether the document being tested is or is not likely to contain embedded malware.
Information query
Patent Agency Ranking
0/0