Inventors:
Jack W. Stokes - North Bend WA, US
John C. Platt - Redmond WA, US
Jonathan M. Keller - Seattle WA, US
Joseph L. Faulhaber - Redmond WA, US
Anil Francis Thomas - Redmond WA, US
Adrian M. Marinescu - Sammamish WA, US
Marius G. Gheorghescu - Redmond WA, US
George Chicioreanu - Redmond WA, US
Assignee:
Microsoft Corporation - Redmond WA
International Classification:
G06F 21/00, G06G 7/62, G06F 17/30, G06F 9/455
US Classification:
726 22, 703 13, 703 23, 707E1701, 707E17032
Abstract:
A method of identifying a malware file using multiple classifiers is disclosed. The method includes receiving a file at a client computer. The file includes static metadata. A set of metadata classifier weights are applied to the static metadata to generate a first classifier output. A dynamic classifier is initiated to evaluate the file and to generate a second classifier output. The method includes automatically identifying the file as potential malware based on at least the first classifier output and the second classifier output.