发明名称 System and method for protecting a computer system from the activity of malicious objects
摘要 <p>Disclosed are systems and methods for protecting a computer from activities of malicious objects. The method comprises: monitoring events of execution of one or more processes on the computer; identifying auditable events among the monitored events, including events of creation, alteration or deletion of files, events of alteration of system registry, and events of network access by processes executed on the computer; recording the identified auditable events in separate file, registry and network event logs; performing a malware check of one or more software objects on the computer; if an object is determined to be malicious, identifying from the file, registry and network event logs the events associated with the malicious object; performing rollback of file events associated with the malicious object; performing rollback of registry events associated with the malicious object; terminating network connections associated with the malicious object.</p>
申请公布号 EP2584484(A1) 申请公布日期 2013.04.24
申请号 EP20110185372 申请日期 2011.10.17
申请人 KASPERSKY LAB, ZAO 发明人 MARTYNENKO, VLADISLAV V.;PAVLYUSHCHIK, MIKHAIL A.;SLOBODYANUK, YURI G.
分类号 G06F21/56 主分类号 G06F21/56
代理机构 代理人
主权项
地址