发明名称 CROSS-VIEW MALWARE DETECTION
摘要 In an example, a cross-view detection engine is disclosed for detecting malware behavior. Malware may attempt to avoid detection by remaining in volatile memory for as long as possible, and writing to disk only when necessary. To avoid detection, the malware may also provide a pseudo-driver at a file system level that performs legitimate-looking dummy operations. A firmware-level driver may simultaneously perform malicious operations. The cross-view detection engine detects this behavior by deconstructing call traces from the file system-level operations, and reconstructing call traces from firmware-level operations. If the traces do not match, the object may be flagged as suspicious.
申请公布号 WO2016048541(A1) 申请公布日期 2016.03.31
申请号 WO2015US46822 申请日期 2015.08.25
申请人 MCAFEE, INC. 发明人 HUNT, SIMON;MANKIN, JENNIFER;ZIMMERMAN, JEFFREY
分类号 G06F21/56;G06F21/50 主分类号 G06F21/56
代理机构 代理人
主权项
地址