发明名称 System and method for security rating of computer processes
摘要 A system, method, and computer program product for secure rating of processes in an executable file for malware presence comprising: (a) detecting an attempt to execute a file on a computer; (b) performing an initial risk assessment of the file; (c) starting a process from code in the file; (d) analyzing an initial risk pertaining to the process and assigning an initial security rating to the process; (e) monitoring the process for the suspicious activities; (f) updating the security rating of the process when the process attempts to perform the suspicious activity; (g) if the updated security rating exceeds a first threshold, notifying a user and continuing execution of the process; and (h) if the updated security rating exceeds a second threshold, blocking the action and terminating the process.
申请公布号 US7530106(B1) 申请公布日期 2009.05.05
申请号 US20080167138 申请日期 2008.07.02
申请人 KASPERSKY LAB, ZAO 发明人 ZAITSEV OLEG V.;GREBENNIKOV NIKOLAY A.;MONASTYRSKY ALEXEY V.;PAVLYUSHCHIK MIKHAIL A.
分类号 G06F11/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址