发明名称 MALWARE AND SPYWARE ATTACK RECOVERY SYSTEM AND METHOD
摘要 A method and computer program product with encoded instructions provides for repeatedly making data backups for files by making a series of snapshots of file storage volumes containing the files. The method and computer product further provide for determining that a malware attack has occurred, identifying corrupted files and, for each corrupted file, scanning the series of snapshots to identify an uncorrupted version of the file. Each corrupted file is restored to an uncorrupted version thereof. An event log contains write events and snapshot creation events corresponding to creation of each of the snapshots. A forensic scan scans the event log to determine modifying writes made by the corrupted files and which modified further files. The further files are restored to unmodified versions thereof. A list of at- risk files includes the corrupted files and the further files and the forensic scan is repeated on the at-risk files.
申请公布号 WO2007056079(A3) 申请公布日期 2009.04.23
申请号 WO2006US42846 申请日期 2006.11.01
申请人 ST. BERNARD SOFTWARE, INC.;MASTERS, DANIEL;NEILL, CHRIS 发明人 MASTERS, DANIEL;NEILL, CHRIS
分类号 G06F12/00 主分类号 G06F12/00
代理机构 代理人
主权项
地址