发明名称 Detecting malicious computer program activity using external program calls with dynamic rule sets
摘要 A stream 14 of external computer program calls made from an application program 2 to an operating system 4 is logged by an anti-malware layer 8 . This stream 14 is examined for a primary set XYZ of external program calls known to be associated with malicious computer program activity. When such a primary set XYZ of external computer program calls is identified, the malicious activity is blocked and the logged stream 14 is examined to determine one or more secondary sets of external program calls which are now added to the set of rules 10 against which the logged stream 14 of external program calls is tested. In this way the set of rules 10 is dynamically adapted so as to more rapidly and proactively identify malicious computer program activity.
申请公布号 US2005154900(A1) 申请公布日期 2005.07.14
申请号 US20040755450 申请日期 2004.01.13
申请人 NETWORKS ASSOCIATES TECHNOLOGY, INC. 发明人 MUTTIK IGOR G.
分类号 G06F21/00;H04L9/32;(IPC1-7):H04L9/32 主分类号 G06F21/00
代理机构 代理人
主权项
地址