发明名称 ROOTKIT DETECTION IN A COMPUTER NETWORK
摘要 Systems and methods are provided for detecting a rootkit by way of a call timing deviation anomaly in a computer. The rootkits may be embedded in the operating system (OS) kernel, an application or other system function. An object call duration baseline is established for durations of object calls (e.g., a system or application call) initiated by the computer, where each object call has an associated call-type and the timing baseline is established on an object call-type basis. Object call durations initiated by the computers are monitored. An object call duration anomaly is detected when the object call duration fails a call duration deviation measurement test, and an indication of the call duration anomaly is generated when detected.
申请公布号 EP3042287(A1) 申请公布日期 2016.07.13
申请号 EP20140841510 申请日期 2014.08.07
申请人 TRIUMFANT, INC. 发明人 QUINN, MITCHELL N.
分类号 G06F11/30;G06F21/55;G06F21/57;H04L29/06 主分类号 G06F11/30
代理机构 代理人
主权项
地址
您可能感兴趣的专利