发明名称 Detecting and responding to malware using link files
摘要 Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for monitoring the generation of link files by processes on a computer and performing protection processes based on whether the link files target malicious objects or are generated by malicious processes. In one aspect, a method includes monitoring for a generation of a first file that includes a target path that points to an object; in response to monitoring the generation of the first file: determining whether the target path is a uniform resource locator; in response to determining that the target path is a uniform resource locator, identifying a process that caused the first file to be generated; determining whether the process is a prohibited process; in response to determining that the process is a prohibited process, performing one or more protection processes on the process and the first file; in response to determining that the process is not a prohibited process, determining whether the uniform resource locator is a prohibited uniform resource locator; in response to determining that the uniform resource locator is a prohibited uniform resource locator, performing one or more protection processes on the process and the first file.
申请公布号 US8863282(B2) 申请公布日期 2014.10.14
申请号 US200912579679 申请日期 2009.10.15
申请人 McAfee Inc. 发明人 Kumar Lokesh;Ramchetty Harinath Vishwanath;Kulkarni Girish R.
分类号 G06F21/00;G06F21/55;H04L29/06;G06F21/51;G06F21/56 主分类号 G06F21/00
代理机构 Patent Capital Group 代理人 Patent Capital Group
主权项 1. A computer-implemented method, comprising: monitoring, by a first computer, a generation of a link file that includes a target path that points to an object; in response to monitoring the generation of the link file: identifying, by the first computer, a process that caused the link file to be generated;determining, by the first computer, whether the process is a prohibited process;in response to determining that the process is a prohibited process, performing, by the first computer, one or more protection processes on the process and the link file;in response to determining that the process is not a prohibited process, determining, by the first computer, whether the link file generates a request to a uniform resource locator;in response to determining that the link file generates a request to a uniform resource locator, determining, by the first computer, whether the uniform resource locator is associated with a malicious resource;in response to determining that the uniform resource locator is associated with a malicious resource, performing, by the first computer, one or more protection processes on the link file.
地址 Santa Clara CA US