发明名称 Identifying malicious applications by statistical analysis of currently running programs and network connections
摘要 A security application running on a computer system generates an application list indicating applications that are currently running. The system identifies network addresses meeting established criteria, such as entries in an IP whitelist or a database of malicious servers. The system then determines whether connections to those addresses have been made within a certain timeframe, and provides the application list LAPP and identified addresses LDOMHITS to another application 712, which may be on an external server 710 receiving information from multiple clients 100, 720, 722, 724. A statistical analysis is then performed to determine which of the applications in the list provided the connection to the suspect address. The analysing application may provide instruction to the system to kill the identified malware. If the operating platform restricts access to these details, the application list can be inferred from installed applications, and the network connections from DNS cache or routing table queries. This allows the detection and elimination of hazardous programs even in systems with restrictive security models.
申请公布号 GB2508174(A) 申请公布日期 2014.05.28
申请号 GB20120021006 申请日期 2012.11.22
申请人 F-SECURE CORPORATION 发明人 ANTTI TIKKANEN;DAAVID HENTUNEN
分类号 G06F21/56;G06F11/34 主分类号 G06F21/56
代理机构 代理人
主权项
地址