发明名称 Method and apparatus for detection of hostile software
摘要 Methods and apparatuses are presented for detecting hostile software in a computer system involving storing a representation of configuration data associated with an operating system for the computer system obtained at a first time, comparing the stored representation of the configuration data obtained at the first time with a representation of the configuration data associated with the operating system for the computer system obtained at a second time, and if deviation is detected between the stored representation of the configuration data obtained at the first time and the representation of the configuration data obtained at the second time, automatically performing at least one remedial measure in response to the deviation detected. In one embodiment of the invention, the configuration data relates to identification of executable code installed in the computer system. The configuration data may be obtained from a registry key in a registry maintained by the operating system.
申请公布号 US2005216749(A1) 申请公布日期 2005.09.29
申请号 US20040808260 申请日期 2004.03.23
申请人 NETWORK EQUIPMENT TECHNOLOGIES 发明人 BRENT MICHAEL D.
分类号 G06F21/00;H04L9/32;H04L29/06;(IPC1-7):H04L9/32 主分类号 G06F21/00
代理机构 代理人
主权项
地址