发明名称 SYSTEM AND METHOD FOR SCANNING HANDLES
摘要 <p>According to an embodiment of the invention a method of detecting malware in a system comprises positioning a filter driver between an operating system for the system and applications or files in the system. The filter driver receives requests for resources from the applications or files and relays the requests to the operating system. The filter driver receives responses to the requests, which include handles; records information associated with the handles in a handle list; and relays the responses to the applications or files, which open the handles. Potential malicious code is detected by analyzing information associated with the open handles, hi particular embodiments, analyzing information associated with the open handles may comprise analyzing system resources referenced by the open handles.</p>
申请公布号 WO2007021585(A1) 申请公布日期 2007.02.22
申请号 WO2006US30444 申请日期 2006.08.03
申请人 COMPUTER ASSOCIATES THINK, INC.;CHANDNANI, ANJALI 发明人 CHANDNANI, ANJALI
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址