发明名称 Method for identifying malicious executables
摘要 <p>In a computer system, a method for detecting a suspected malware behavior, according to which a plurality of activities on a computer system that were conducted within a given time frame are monitored during the installation of a suspected file. The monitored activities are recorded and the monitored/recorded activities are compared with patterns of malware behavior, stored in a database. Upon detecting a suspicious program, the recorded monitored activities are provided for further analysis to be performed by appropriate software removal tools.</p>
申请公布号 EP2701092(A1) 申请公布日期 2014.02.26
申请号 EP20130171197 申请日期 2013.06.10
申请人 TRUSTEER LTD. 发明人 KLEIN, AMIT;BOODAEI, MICHAEL
分类号 G06F21/55 主分类号 G06F21/55
代理机构 代理人
主权项
地址