Information security – Monitoring or scanning of software or data including attack... – Intrusion detection
Reexamination Certificate
2011-07-12
2011-07-12
Barron, Jr., Gilberto (Department: 2432)
Information security
Monitoring or scanning of software or data including attack...
Intrusion detection
C726S013000, C713S188000
Reexamination Certificate
active
07979907
ABSTRACT:
A system and methods for detecting malicious executable attachments at an email processing application of a computer system using data mining techniques. The email processing application may be located at the server or at the client or host. The executable attachments are filtered from said email, and byte sequence features are extracted from the executable attachment. The executable attachments are classified by comparing the byte sequence feature of the executable attachment to a classification rule set derived from byte sequence features of a data set of known executables having a predetermined class in a set of classes, e.g., malicious or benign. The system is also able to classify executable attachments as borderline when the difference between the probability that the executable is malicious and the probability that the executable is benign are within a predetermined threshold. The system can notify the user when the number of borderline attachments exceeds the threshold in order to refine the classification rule set.
REFERENCES:
patent: 5832208 (1998-11-01), Chen et al.
patent: 6016546 (2000-01-01), Kephart et al.
patent: 6161130 (2000-12-01), Horvitz et al.
patent: 6732149 (2004-05-01), Kephart
patent: 2004/0073617 (2004-04-01), Milliken et al.
patent: 2009/0132669 (2009-05-01), Milliken et al.
Bhattacharyya Manasi
Eskin Eleazar
Salvatore J. Stolfo
Schultz Matthew G.
Zadok Erez
Baker & Botts LLP
Barron Jr. Gilberto
Nobahar Abdulhakim
The Trustees of Columbia University in the City of New York
LandOfFree
Systems and methods for detection of new malicious executables does not yet have a rating. At this time, there are no reviews or comments for this patent.
If you have personal experience with Systems and methods for detection of new malicious executables, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Systems and methods for detection of new malicious executables will most certainly appreciate the feedback.
Profile ID: LFUS-PAI-O-2703040