发明名称 Method and system for detecting infection of an operating system
摘要 A method and system for detecting that a software system has been infected by software that attempts to hide properties related to the software system is provided. A detection system identifies that a suspect operating system has been infected by malware by comparing properties related to the suspect operating system as reported by the suspect operating system to properties as reported by another operating system that is assumed to be clean. The detection system compares the reported properties to the actual properties to identify any significant differences. A significant difference, such as the presence of an actual file not reported by the suspect operating system, may indicate that the suspect storage device is infected.
申请公布号 US2006031673(A1) 申请公布日期 2006.02.09
申请号 US20040997768 申请日期 2004.11.23
申请人 MICROSOFT CORPORATION 发明人 BECK DOUGLAS R.;JOHNSON AARON R.;ROUSSEV ROUSSI A.;VERBOWSKI CHAD E.;VO BINH D.;WANG YI-MIN
分类号 H04L9/00 主分类号 H04L9/00
代理机构 代理人
主权项
地址