Patent attributes
A method of determining a category of a malware file, using a malware determination system comprising a machine learning algorithm, the method comprising obtaining a file, which is assumed to constitute malware file, by the malware determination system, building a data structure representative of features present in said file, based on features present in at least one dictionary, wherein said dictionary stores at least, for each of one or more of categories Ci out of a plurality of N categories of malware files, with i from 1 to N and N>2, one or more features which are specific to said category Ci with respect to all other N−1 categories Cj, with j different from i, according to at least one first specificity criteria, feeding the data structure to the machine learning algorithm of the malware determination system, and providing prospects representative of one or more malware categories to which said file belongs, based on said data structure.