首页>
外国专利>
CORRELATION-BASED DETECTION OF EXPLOIT ACTIVITY
CORRELATION-BASED DETECTION OF EXPLOIT ACTIVITY
展开▼
机译:基于相关性的开发活动检测
展开▼
页面导航
摘要
著录项
相似文献
摘要
A security agent implemented on a monitored computing device is described herein. The security agent is configured to receive an event notification indicative of execution of an object and store, in a data structure on the monitored computing device, information associated with the event notification and the object. The security agent is further configured to receive an event notification indicative of an occurrence on the monitored computing device of an activity. Based at least in part on the stored information, the security agent correlates the occurrence of the activity with the execution of the object and generates an exploit detection event based on the correlating.
展开▼