发明名称 Malicious software detection via memory analysis
摘要 To detect the presence of malicious software in a system, selected data in memory of the system is stored in a designated storage location and analyzed by a known safe operating system. In an example configuration, a snapshot of system memory is downloaded to a dedicated device coupled to the motherboard of the system. A clean, uncorrupted operating system is loaded into the dedicated device, and the snapshot is analyzed utilizing the clean operating system. If malicious software is detected, the system is repaired using the clean operating system. In an example embodiment, this process is initiated when the system goes into a hibernation state, and/or during a system restoration operation.
申请公布号 US2008016572(A1) 申请公布日期 2008.01.17
申请号 US20060485066 申请日期 2006.07.12
申请人 MICROSOFT CORPORATION 发明人 BURKHARDT RYAN M.;POLYAKOV ALEXEY
分类号 G06F12/14 主分类号 G06F12/14
代理机构 代理人
主权项
地址