发明名称 System, method and computer program product for remote rootkit detection
摘要 A security system may detect a rootkit by detecting a filesystem configuration of the first system and comparing the filesystem configuration to a known valid filesystem configuration of a second system. The known valid filesystem configuration may be the filesystem configuration of a protected second system, or may be stored in a protected area of the second system. The first and second system may be part of a single device. The filesystem configuration of the first system and the known valid filesystem configuration are compared and differences are analyzed to determine if they are indicative of a rootkit. If a rootkit is detected, some embodiments may provide tools to clean, delete, or quarantine the rootkit. The second system may be provided by a security provider.
申请公布号 US7975298(B1) 申请公布日期 2011.07.05
申请号 US20060392311 申请日期 2006.03.29
申请人 MCAFEE, INC. 发明人 VENKATASUBRAHMANYAM KRISHNAPUR NARASIMHAMURTHY
分类号 G06F11/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址