Inventors:
Robert Conrad - Culver City CA, US
Joseph Chen - Los Angeles CA, US
Assignee:
Symantec Corporation - Mountain View CA
International Classification:
G06F 12/14, G06F 7/04, G06F 11/30, G06F 15/173, G06F 15/16, H04L 29/06, H04L 9/32
US Classification:
726 24, 726 25, 726 26, 713151, 713165, 713168, 713187, 713188, 709224, 709225, 709232
Abstract:
The prevalence rate of a file to be subject to behavior based heuristics analysis is determined, and the aggressiveness level to use in the analysis is adjusted, responsive to the prevalence rate. The aggressiveness is set to higher levels for lower prevalence files and to lower levels for higher prevalence files. Behavior based heuristics analysis is applied to the file, using the set aggressiveness level. In addition to setting the aggressiveness level, the heuristic analysis can also comprise dynamically weighing lower prevalence files as being more likely to be malicious and higher prevalence files as being less likely. Based on the applied behavior based heuristics analysis, it is determined whether or not the file comprises malware. If it is determined that the file comprises malware, appropriate steps can be taken, such as blocking, deleting, quarantining and/or disinfecting the file.