发明名称 Protecting User Mode Processes From Improper Tampering or Termination
摘要 In one embodiment, a malware protection system may protect a computing system from a malware event. A data storage device 150 may store a watchdog filter driver 240 integrated with an operating system kernel 210. A processor 120 may intercept a process access to an application process 220 with the watchdog filter driver 240 to detect a malware event. The processor 120 may use the watchdog filter driver 240 to determine an originating process for the malware event.
申请公布号 US2011209219(A1) 申请公布日期 2011.08.25
申请号 US20100713151 申请日期 2010.02.25
申请人 MICROSOFT CORPORATION 发明人 ZEITLIN ELI;AXELROD ARNON;THOMAS ANIL FRANCIS;MAROK KANWALJIT
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址