发明名称 Portable security device and methods for detection and treatment of malware
摘要 Disclosed is a portable security device and method for detection and treatment of computer malware. The security device includes a communication interface for connecting to a computer, a memory for storing a set of data for use in malware detection experiments, and an antivirus engine configured to perform one or more malware detection experiments on the computer. A malware detection experiment includes simulating a connection to the computer of a data storage device containing a predefined set of data. The antivirus engine further configured to identify modifications in the set of data contained in the data storage device after termination of one or more malware detection experiments, analyze a modified set of data for presences of computer malware, determine a treatment mechanism for the detected malware, perform treatment of the detected malware on the computer, and generate user reports.
申请公布号 US8863289(B2) 申请公布日期 2014.10.14
申请号 US201213482490 申请日期 2012.05.29
申请人 Kaspersky Lab ZAO 发明人 Zaitsev Oleg V.
分类号 G06F21/00;G06F21/56 主分类号 G06F21/00
代理机构 Arent Fox LLP 代理人 Arent Fox LLP ;Fainberg Michael
主权项 1. A method for detection and treatment of computer malware, the method comprising: connecting a portable security device to a computer; performing at least one malware detection experiment by the security device on the computer, wherein the at least one malware detection experiment includes simulating by the security device a connection to the computer of a simulated data storage device containing a predefined set of data, wherein the connection of the simulated data storage device to the computer is simulated by transferring at least a portion of the predefined set of data by the security device to the computer; identifying modifications in the set of data contained in the simulated data storage device after termination of the at least one malware detection experiment; performing antivirus analysis of the modified set of data to determine if the modifications to the set of data were performed by a malware on the computer; determining a treatment mechanism for the detected malware; and performing treatment of the detected malware on the computer.
地址 Moscow RU