发明名称 KERNEL LEVEL SECURITY AGENT
摘要 <p>A kernel- level security agent is described herein. The kernel -level security agent is configured to observe events, filter the observed events using configurable filters , route the filtered events to one or more event consumers , and utilize the one or more event consumers to take action based at least on one of the filtered events. In some implementations, the kernel- level security agent detects a first action associated with malicious code, gathers data about the malicious code, and in response to detecting subsequent action(s) of the malicious code ,performs a preventative action. The kernel- level security agent may also deceive an adversary associated with malicious code. Further, the kernel -level security agent may utilize a model representing chains of execution activities and may take action based on those chains of execution activities.</p>
申请公布号 IN9583DEN2014(A) 申请公布日期 2015.07.17
申请号 IN2014DE09583 申请日期 2014.11.13
申请人 CROWDSTRIKE, INC., 发明人 DIEHL, DAVID F.;ALPEROVITCH, DMITRI;IONESCU, ION0 ALEXANDRU;KURTZ, GEORGE, ROBERT
分类号 G06F21/50;G06F9/22;G06F15/16 主分类号 G06F21/50
代理机构 代理人
主权项
地址