发明名称 Detecting and responding to malware using link files
摘要 Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for monitoring the generation of link files by processes on a computer and performing protection processes based on whether the link files target malicious objects or are generated by malicious processes. In one aspect, a method includes monitoring for a generation of a first file that includes a target path that points to an object; in response to monitoring the generation of the first file: determining whether the target path is a uniform resource locator; in response to determining that the target path is a uniform resource locator, identifying a process that caused the first file to be generated; determining whether the process is a prohibited process; in response to determining that the process is a prohibited process, performing one or more protection processes on the process and the first file; in response to determining that the process is not a prohibited process, determining whether the uniform resource locator is a prohibited uniform resource locator; in response to determining that the uniform resource locator is a prohibited uniform resource locator, performing one or more protection processes on the process and the first file.
申请公布号 AU2010306623(A1) 申请公布日期 2012.05.10
申请号 AU20100306623 申请日期 2010.10.15
申请人 MCAFEE, INC. 发明人 KUMAR, LOKESH;RAMCHETTY, HARINATH VISHWANATH;KULKARNI, GIRISH R.
分类号 G06F11/30;G06F21/06;G06F21/22 主分类号 G06F11/30
代理机构 代理人
主权项
地址