发明名称 Process profiling for behavioral anomaly detection
摘要 An anomalous process behavior manager uses statistical information concerning running processes to detect and manage process behavioral anomalies. The anomalous process behavior manager collects per process statistical data over time, such as resource allocation statistics and user interaction statistics. Current collected statistical data is analyzed against corresponding historical statistical data to determine whether processes are behaving in expected ways relative to past performance. Appropriate corrective steps are taken when it is determined that a process is behaving anomalously. For example, the process's blocking exclusions can be revoked, the process can be uninstalled, the process and/or the computer can be scanned for malicious code, the user can be alerted and/or relevant information can be shared with other parties.
申请公布号 US8171545(B1) 申请公布日期 2012.05.01
申请号 US20070674934 申请日期 2007.02.14
申请人 COOLEY SHAUN;MCCORKENDALE BRUCE;SYMANTEC CORPORATION 发明人 COOLEY SHAUN;MCCORKENDALE BRUCE
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址