跳到主体内容

Kaspersky Lab Patents Automated False-Positive Testing Technology Based on Machine Learning Algorithms

2015年11月23日

Kaspersky Lab has patented a technology that allows for effective false-positive testing of heuristic signatures describing groups of similar malicious files

Kaspersky Lab has patented a technology that allows for effective false-positive testing of heuristic signatures describing groups of similar malicious files. This patent is the latest addition to the arsenal of advanced technologies used by the company in combating cyberthreats that allow for reliable automation of a large proportion of routine virus analysis tasks.

The detection rules, which are automatically created by processing limited amounts of newly discovered malicious files, describe groups of malicious objects as combinations of various characteristics. These characteristics include, for example, sequences of system calls and events that are common for malicious objects and uncommon for whitelisted files.

The technology, entitled “System and method for evaluating malware detection rules”, allows Kaspersky Lab to reliably test the automatically created detection rules to determine whether they correctly describe the groups of malicious files in such a way that legitimate ones are not affected (i.e. the possibility of generating false positives is greatly reduced). It works by testing these detection rules in the Kaspersky Lab infrastructure and comparing all files found to fall under the description with the set of known benign (or whitelisted) files and a larger set of known malicious objects. If no similarities are found, the detection rule is considered to be accurate and is rolled out to the users.

“As the amount of malicious files which we encounter every day exceedshundreds of thousandsand keeps growing, we at Kaspersky Lab have been automating a number of virus analysis tasks. For example, such tasks as finding similarities between different malicious files so that we could create heuristic detection rules that describe groups of objects instead of single files. The patented technology complements the set of machine learning tools our experts are using so that they have more time to concentrate on the most advanced and sophisticated threats”, said Timur Biyachuev, Director Anti-Malware Research, Kaspersky Lab.

The patented technology (US Patent No. 9171155) is implemented in the following products: Kaspersky Internet Security, Kaspersky Total Security Multi-Device, Kaspersky Endpoint Security for Business.

Kaspersky Lab continues to develop and patent new data protection technologies. By the end of October 2015, the company had 343 patents in Russia, the US, China and Europe, with 324 more patent applications filed.

Kaspersky Lab Patents Automated False-Positive Testing Technology Based on Machine Learning Algorithms

Kaspersky Lab has patented a technology that allows for effective false-positive testing of heuristic signatures describing groups of similar malicious files
Kaspersky logo

关于卡巴斯基

卡巴斯基是一家成立于1997年的全球网络安全和数字隐私公司。卡巴斯基以“网络免疫”理念引领行业创新,致力于保护消费者、企业、关键基础设施和政府机构免受网络威胁,迄今为止已保护超过 10 亿台设备。

卡巴斯基秉持“Cybersecurity True to Business”的理念,专注于交付明确成果、保障营收、减轻团队负担并避免业务中断。卡巴斯基深厚的威胁情报和安全专业知识不断转化为创新解决方案和服务,服务于从小型企业到大型集团等各种规模的组织,将成熟的 AI 驱动型保护技术与简洁高效的管理和专家支持相结合。

卡巴斯基的解决方案经独立测试认可,深受全球数百万个人用户及近 20 万家企业的信赖,帮助客户更早识别威胁、更快速响应,以更强的信心与自由空间开展业务,保护对客户至关重要的资产。了解更多详情,请访问 www.kaspersky.com.cn

相关文章 企业新闻