发明名称 SYSTEMS AND METHODS FOR IDENTIFYING A SOURCE OF A SUSPECT EVENT
摘要 <p>A computer-implemented method for identifying a source of a suspect event is described. In one embodiment, system events may be registered in a database. A suspicious event associated with a first process may be detected and the first process may be identified as being one of a plurality of potential puppet processes. The registered system events in the database may be queried to identify a second process, where the second process is detected as launching the first process.</p>
申请公布号 WO2015153037(A1) 申请公布日期 2015.10.08
申请号 WO2015US18412 申请日期 2015.03.03
申请人 SYMANTEC CORPORATION 发明人 PEREIRA, SHANE
分类号 G06F21/55 主分类号 G06F21/55
代理机构 代理人
主权项
地址