发明名称 SYSTEM AND METHOD FOR REDUCING LOAD ON AN OPERATING SYSTEM WHEN EXECUTING ANTIVIRUS OPERATIONS
摘要 <p>An initial trust status is assigned to a first object, the trust status representing one of either a relatively higher trust level or a relatively lower trust level. Based on the trust status, the first object is associated with an event type to be monitored, where the event type is selected from among: essential events, occurrence of which is informative as to trust status evaluating for an object, and critical events, including the essential events, and additional events, occurrence of which is informative as to execution of suspicious code. Occurrences of events relating to the first object are monitored. In response to the first object being assigned the relatively higher trust level, only the essential events are monitored. In response to the first object being assigned the relatively lower trust level, the critical events are monitored. A need for performing malware analysis is determined based on the trust status of the first object and the event type. In response to determination of the need for performing the malware analysis, the malware analysis for the first object is either performed, or not.</p>
申请公布号 EP2881883(A1) 申请公布日期 2015.06.10
申请号 EP20140183230 申请日期 2014.09.02
申请人 KASPERSKY LAB, ZAO 发明人 SOBKO, ANDREY V.;YUDIN, MAXIM V.;MEZHUEV, PAVEL N.;GODUNOV, ILYA B.;SHIROKY, MAXIM A.
分类号 G06F21/56 主分类号 G06F21/56
代理机构 代理人
主权项
地址