发明名称 Method and apparatus for performing a reputation based analysis on a malicious infection to secure a computer
摘要 A method and apparatus for performing a reputation based analysis on a malicious infection to secure a computer. In one embodiment, the method includes monitoring application activity occurring at computers, generating reputation information associated with the application activity, in response to a malicious infection to at least one of the computers, examining the reputation information to access unreputed portions of the application activity that occurred at the at least one of the computers and determining a malicious signature based on the unreputed portions of the application activity.
申请公布号 US8839432(B1) 申请公布日期 2014.09.16
申请号 US201012752727 申请日期 2010.04.01
申请人 Symantec Corporation 发明人 Patil Deepak
分类号 G06F21/00;G06F21/56 主分类号 G06F21/00
代理机构 Wilmer Cutler Pickering Hale and Dorr LLP 代理人 Wilmer Cutler Pickering Hale and Dorr LLP
主权项 1. A method for performing a reputation based analysis on a malicious infection to secure a computer, comprising: monitoring, using at least one processor, application activity occurring at computers; generating, using at least one processor, reputation information associated with the application activity; in response to a malicious infection to at least one of the computers, examining, using at least one processor, the reputation information from memory to access unreputed portions of the application activity that occurred at the at least one of the computers; and determining, using at least one processor, a malicious signature based on the unreputed portions of the application activity by at least transforming the application activity and the reputation information into the malicious signature, wherein the malicious signature comprises information for identifying malware or malware variants and a grouping of side effects associated with the identified malware or malware variants.
地址 Mountain View CA US