Invention Grant
- Patent Title: Using telemetry to reduce malware definition package size
-
Application No.: US14341183Application Date: 2014-07-25
-
Publication No.: US09613213B2Publication Date: 2017-04-04
- Inventor: Shane Pereira , Carey S. Nachenberg
- Applicant: Symantec Corporation
- Applicant Address: US CA Mountain View
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Mountain View
- Agency: Patent Law Works LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/56

Abstract:
Clients send telemetry data to a cloud server, where the telemetry data includes security-related information such as file creations, timestamps and malware detected at the clients. The cloud server analyzes the telemetry data to identify malware that is currently spreading among the clients. Based on the analysis of the telemetry data, the cloud server segments malware definitions in a cloud definition database into a set of local malware definitions and a set of cloud malware definitions. The cloud server provides the set of local malware definitions to the clients as a local malware definition update, and replies to cloud definition lookup requests from clients with an indication of whether a file identified in a request contains malware. If the file is malicious, the client remediates the malware using local malware definition update.
Public/Granted literature
- US20140337979A1 Using Telemetry to Reduce Malware Definition Package Size Public/Granted day:2014-11-13
Information query