会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 2. 发明授权
    • Identification of electronic documents that are likely to contain embedded malware
    • 识别可能包含嵌入式恶意软件的电子文档
    • US09177142B2
    • 2015-11-03
    • US13274077
    • 2011-10-14
    • Rodrigo Ribeiro Montoro
    • Rodrigo Ribeiro Montoro
    • G06F21/56
    • G06F21/562
    • The present invention provides a method for determining the likelihood that an electronic document contains embedded malware. After parsing or sequencing an electronic document, the metadata structures that make up the document are analyzed. A number of pre-established rules are then applied with respect to certain metadata structures that are indicative of embedded malware. The application of these rules results in the generation of a score for the electronic document being tested for embedded malware. The score is then compared to a threshold value, where the threshold value was previously generated based on a statistical model relating to electronic documents having the same format as the document being tested. The result of the comparison can then be used to determine whether the document being tested is or is not likely to contain embedded malware.
    • 本发明提供了一种用于确定电子文档包含嵌入式恶意软件的可能性的方法。 分析或排序电子文档后,分析组成文档的元数据结构。 然后针对指示嵌入式恶意软件的某些元数据结构应用许多预先建立的规则。 这些规则的应用导致为嵌入式恶意软件测试的电子文档生成分数。 然后将分数与阈值进行比较,其中基于与具有与被测试文档相同格式的电子文档的统计模型,先前生成阈值。 然后可以使用比较的结果来确定被测试的文档是否或不可能包含嵌入式恶意软件。
    • 3. 发明申请
    • IDENTIFICATION OF ELECTRONIC DOCUMENTS THAT ARE LIKELY TO CONTAIN EMBEDDED MALWARE
    • 识别包含嵌入式恶意软件的电子文件
    • US20130097705A1
    • 2013-04-18
    • US13274077
    • 2011-10-14
    • Rodrigo Ribeiro Montoro
    • Rodrigo Ribeiro Montoro
    • G06F21/00
    • G06F21/562
    • The present invention provides a method for determining the likelihood that an electronic document contains embedded malware. After parsing or sequencing an electronic document, the metadata structures that make up the document are analyzed. A number of pre-established rules are then applied with respect to certain metadata structures that are indicative of embedded malware. The application of these rules results in the generation of a score for the electronic document being tested for embedded malware. The score is then compared to a threshold value, where the threshold value was previously generated based on a statistical model relating to electronic documents having the same format as the document being tested. The result of the comparison can then be used to determine whether the document being tested is or is not likely to contain embedded malware.
    • 本发明提供了一种用于确定电子文档包含嵌入式恶意软件的可能性的方法。 分析或排序电子文档后,分析组成文档的元数据结构。 然后针对指示嵌入式恶意软件的某些元数据结构应用许多预先建立的规则。 这些规则的应用导致为嵌入式恶意软件测试的电子文档生成分数。 然后将分数与阈值进行比较,其中基于与具有与被测试文档相同格式的电子文档的统计模型,先前生成阈值。 然后可以使用比较的结果来确定被测试的文档是否或不可能包含嵌入式恶意软件。