发明名称 シグネチャとは無関係の、システム挙動に基づいた、マルウェア検出
摘要 A method, system, and computer program product for detecting malware based upon system behavior. At least one process expected to be active is identified for a current mode of operation of a processing system comprising one or more resources. An expected activity level of the one or more resources of the processing system is calculated based upon the current mode of operation and the at least one process expected to be active. An actual activity level of the plurality of resources is determined. If a deviation is detected between the expected activity level and the actual activity level, a source of unexpected activity is identified as a potential cause of the deviation. Policy guidelines are used to determine whether the unexpected activity is legitimate. If the unexpected activity is not legitimate, the source of the unexpected activity is classified as malware.
申请公布号 JP5632097(B2) 申请公布日期 2014.11.26
申请号 JP20130543413 申请日期 2011.12.13
申请人 发明人
分类号 G06F21/56 主分类号 G06F21/56
代理机构 代理人
主权项
地址