Patent 8424091 was granted and assigned to Trend Micro on April, 2013 by the United States Patent and Trademark Office.
A system for locally detecting computer security threats in a computer network includes a processing engine, a fingerprint engine, and a detection engine. Data samples are received in the computer network and grouped by the processing engine into clusters. Clusters that do not have high false alarm rates are passed to the fingerprint engine, which generates fingerprints for the clusters. The detection engine scans incoming data for computer security threats using the fingerprints.