发明名称 Using behavior blocking mobility tokens to facilitate distributed worm detection
摘要 Behavior blocking mobility token managers track movement of suspicious files within a network. A behavior blocking mobility token manager on a source computer detects an attempt by a process on the source computer to write a file to a target computer. The behavior blocking mobility token manager determines a suspicion level associated with the process, and writes a behavior blocking mobility token containing at least the suspicion level associated with the process to the target computer. A behavior blocking mobility token manager on the target computer detects that a behavior blocking mobility token is being written to the target computer. The behavior blocking mobility token manager reads the behavior blocking mobility token, and determines a suspicion level of the file associated with the behavior blocking mobility token, responsive to contents of the behavior blocking mobility token.
申请公布号 US7690034(B1) 申请公布日期 2010.03.30
申请号 US20040938047 申请日期 2004.09.10
申请人 SYMANTEC CORPORATION 发明人 SALLAM AHMED
分类号 H04L29/00 主分类号 H04L29/00
代理机构 代理人
主权项
地址