发明名称 Detecting and countering malicious code in enterprise networks
摘要 A system and method for detecting and countering malicious code in an enterprise network are provided. A pattern recognition processor monitors local operations on a plurality of local machines connected through an enterprise network, to detect irregular local behavior patterns. An alert may be generated after an irregularity in behavior pattern on a local machine is detected. Irregular behavior alerts from a plurality of local machines are analyzed. If similar alerts are received from at least a threshold number of local machines over a corresponding period of time, one or more countermeasure operations are selected based on the analysis of the irregular behavior alerts. The selected countermeasure operations are communicated to the local machines and performed by the local machines.
申请公布号 US2003200464(A1) 申请公布日期 2003.10.23
申请号 US20030414117 申请日期 2003.04.15
申请人 COMPUTER ASSOCIATES THINK, INC. 发明人 KIDRON YARON
分类号 G06F21/22;G06F13/00;G06F15/00;H04L12/66;H04L29/06;(IPC1-7):G06F11/30;G06F15/173 主分类号 G06F21/22
代理机构 代理人
主权项
地址