发明名称 Method and system for discrete stateful behavioral analysis
摘要 A method for analyzing a computing system includes the steps of at a first moment in time, scanning the resources of the computing system for indications of malware, at a second moment in time scanning the resources of the computing system for indications of malware and determining the system executable objects loaded on the computing system, determining malware system changes, identifying a relationship between the malware system changes and the system executable objects loaded on the computing system, and identifying as suspected malware the system executable objects loaded on the computing system which have a relationship with the malware system changes. The malware system changes include differences between the results of scanning the resources of the computing system for indications of malware at the second and first moment of time.
申请公布号 US9202048(B2) 申请公布日期 2015.12.01
申请号 US201213669209 申请日期 2012.11.05
申请人 McAfee, Inc. 发明人 Sallam Ahmed Said
分类号 G06F11/00;G06F21/55 主分类号 G06F11/00
代理机构 Baker Botts L.L.P. 代理人 Baker Botts L.L.P.
主权项 1. A method for analyzing a computing system, comprising: at a first moment in time, scanning the resources of the computing system for indications of malware; at a second moment in time: scanning the resources of the computing system for indications of malware; and,determining one or more system executable objects loaded on the computing system; determining one or more system changes, wherein the system changes comprise one or more differences between the results of scanning the resources of the computing system for indications of malware at the second moment of time and the first moment in time; identifying a relationship between the system changes and the one or more system executable objects loaded on the computing system; identifying as malicious the one or more system executable objects loaded on the computing system for which a relationship with the system changes has been identified.
地址 Santa Clara CA US
您可能感兴趣的专利