Mandiant, Inc.
Malware detection verification and enhancement by coordinating endpoint and malware detection systems

Last updated:

Abstract:

Computerized techniques to determine and verify maliciousness of an object are described. An endpoint device, during normal processing of an object, identifies the object as suspicious in response to detected features of the object and coordinates further analysis with a malware detection system. The malware detection system processes the object, collects features related to processing, and analyzes the features of the suspicious object to classify as malicious or benign. Correlation of the features captured by the endpoint device and the malware detection system may verify a classification by the malware detection system of maliciousness of the content. The malware detection system may communicate with the one or more endpoint devices to influence detection and reporting of behaviors by those device(s).

Status:
Grant
Type:

Utility

Filling date:

26 Jun 2017

Issue date:

29 Oct 2019