SYSTEMS AND METHODS FOR IDENTIFYING SUSPICIOUS SINGLETON FILES USING CORRELATIONAL PREDICTORS
Patent №
US 10,073,983
Granted
2018-09-11
Filed 2015
Owner
SYMANTEC CORPORATION
Lab
—
AI components
2
kr · planning
Assignment
Recorded
Dataset
AIPD
2023_r1 edition
Application
14966502
The disclosed computer-implemented method for identifying suspicious singleton files using correlational predictors may include (1) identifying a set of known-clean computing devices that include no singleton files, (2) detecting at least one software component that is installed on a threshold number of the known-clean computing devices, (3) identifying an unvindicated computing device whose infection status is unknown, (4) determining that, in addition to being installed on the threshold number of known-clean computing devices, the software component is installed on the unvindicated computing device, (5) determining that the unvindicated computing device includes at least one singleton file, and then (6) classifying the singleton file as suspicious in response to determining that (A) the software component is installed on the unvindicated computing device and (B) the unvindicated computing device includes the singleton file. Various other methods, systems, and computer-readable media are also disclosed.
AI classification
Ownership
SYMANTEC CORPORATION
assignment · 372720306
Assignors
LI, BO, ROUNDY, KEVIN ALEJANDRO, GATES, CHRISTOPHER
On an employer assignment, the assignors are typically the inventors.