发明名称 Method, system and computer program product for detecting at least one of security threats and undesirable computer files
摘要 Method, system and computer program product for detecting at least one of security threats and undesirable computer files are provided. A first method includes receiving a data stream which represents outbound, application layer messages from a first computer process to at least one second computer process. The computer processes are implemented on one or more computers. The method further includes monitoring the data stream to detect a security threat based on a whitelist having entries which contain metadata. The whitelist describes legitimate application layer messages based on a set of heuristics. The method still further includes generating a signal if a security threat is detected. A second method includes comparing a set of computer files with a whitelist which characterizes all legitimate computer files. The whitelist contains one or more entries. Each of the entries describe a plurality of legitimate computer files.
申请公布号 US2009158430(A1) 申请公布日期 2009.06.18
申请号 US20080317056 申请日期 2008.12.18
申请人 发明人 BORDERS KEVIN R.
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址