发明名称 MALWARE DETECTION BY APPLICATION MONITORING
摘要 A method of detecting malware on a computer system. The method comprises monitoring the behavior of trusted applications running on the computer system and, in the event that unexpected behavior of an application is detected, identifying a file or files responsible for the unexpected behavior and tagging the file(s) as malicious or suspicious. The unexpected behavior of the application may comprise, for example, dropping executable files, performing modifications to a registry branch which is not a registry branch of the application, reading a file type class which is not a file type class of the application, writing portable executable (PE) files, and crashing and re-starting of the application.
申请公布号 EP2486507(B1) 申请公布日期 2016.08.17
申请号 EP20100760980 申请日期 2010.09.22
申请人 F-SECURE CORPORATION 发明人 NIEMELÄ, JARNO;PALOMÄKI, PIRKKA
分类号 G06F21/56;G06F21/57 主分类号 G06F21/56
代理机构 代理人
主权项
地址