发明名称 COMPLEX SCORING FOR MALWARE DETECTION
摘要 Described systems and methods allow protecting a computer system from malware such as viruses, Trojans, and spyware. For each of a plurality of executable entities (such as processes and threads executing on the computer system), a scoring engine records a plurality of evaluation scores, each score determined according to a distinct evaluation criterion. Every time an entity satisfies an evaluation criterion (e.g, performs an action), the respective score of the entity is updated. Updating a score of an entity may trigger score updates of entities related to the respective entity, even when the related entities are terminated, i.e., no longer active. Related entities include, among others, a parent of the respective entity, and/or an entity injecting code into the respective entity. The scoring engine determines whether an entity is malicious according to the plurality of evaluation scores of the respective entity.
申请公布号 EP3053087(A1) 申请公布日期 2016.08.10
申请号 EP20140805695 申请日期 2014.09.25
申请人 BITDEFENDER IPR MANAGEMENT LTD. 发明人 LUKACS, SANDOR;TOSA, RAUL-VASILE;BOCA, PAUL-DANIEL;HAJMASAN, GHEORGHE-FLORIN;LUTAS, ANDREI-VLAD
分类号 G06F21/56 主分类号 G06F21/56
代理机构 代理人
主权项
地址