Invention Grant
- Patent Title: Detecting malware through package behavior
-
Application No.: US13948026Application Date: 2013-07-22
-
Publication No.: US09361460B1Publication Date: 2016-06-07
- Inventor: Sourabh Satish
- Applicant: Symantec Corporation
- Applicant Address: US CA Mountain View
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Mountain View
- Agency: Fenwick & West LLP
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/56

Abstract:
A file on a computer system is evaluated against trust criteria to determine whether the file is compatible with the trust criteria. Responsive to the file being incompatible with the trust criteria, the file is assigned to a package. Files assigned to the package are tracked to determine whether the files collectively perform malicious behavior. The package is convicted as malware responsive to the files in the package collectively performing malicious behavior.
Information query