首页> 外国专利> REAL-TIME DETECTION OF AND PROTECTION FROM MALWARE AND STEGANOGRAPHY IN A KERNEL MODE

REAL-TIME DETECTION OF AND PROTECTION FROM MALWARE AND STEGANOGRAPHY IN A KERNEL MODE

机译:内核模式下恶意软件和象形文字的实时检测和防护

摘要

A method for real-time detection of malware in a Kernel mode includes detecting a file operation request initiated by a process running in user mode. Malware detection analytics is performed on a file buffer associated with the detected file operation request to detect behavior indicating presence of malware. Responsive to detecting the behavior indicating the presence of the malware, the process responsible for initiating the detected file operation request is identified. A search for the identified process is performed on one or more of a blacklist of programs and a whitelist of programs to determine whether the identified process is a trusted process. Responsive to determining that the identified process is not a trusted process, a malware remediation action is executed against the identified process. Information describing the malware is transmitted to a client device.
机译:一种用于以内核模式实时检测恶意软件的方法,包括检测由以用户模式运行的进程发起的文件操作请求。在与检测到的文件操作请求相关联的文件缓冲区上执行恶意软件检测分析,以检测指示恶意软件存在的行为。响应于检测到指示恶意软件的存在的行为,标识了负责发起检测到的文件操作请求的过程。在程序黑名单和程序白名单中的一个或多个上执行对标识的进程的搜索,以确定标识的进程是否是受信任的进程。响应于确定所标识的进程不是受信任的进程,针对所标识的进程执行恶意软件补救措施。描述恶意软件的信息被传输到客户端设备。

著录项

  • 公开/公告号EP3635603A1

    专利类型

  • 公开/公告日2020-04-15

    原文格式PDF

  • 申请/专利权人 CYEMPTIVE TECHNOLOGIES INC.;

    申请/专利号EP20180809684

  • 发明设计人 MACLEOD STEWART P.;PIKE ROBERT;

    申请日2018-05-30

  • 分类号G06F21/56;

  • 国家 EP

  • 入库时间 2022-08-21 11:40:11

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号