| CPC G06F 21/56 (2013.01) [G06N 3/08 (2013.01); G06F 2221/034 (2013.01)] | 20 Claims |

|
1. An apparatus, comprising:
a memory that stores an instruction; and
a processor configured to execute the instruction to
determine a file type of a file,
identify an access operation on the file,
perform a statistical analysis of the file to determine a difference between an expected byte distribution value of the file type and a computed byte distribution value of the file, and
performing a remediation at least in part based on the access operation.
|