首页> 外国专利> METHOD FOR DETECTING ANOMALOUS EVENTS ON BASIS OF CONVOLUTION ARRAY OF SAFETY EVENTS

METHOD FOR DETECTING ANOMALOUS EVENTS ON BASIS OF CONVOLUTION ARRAY OF SAFETY EVENTS

机译:安全事件卷积矩阵的异常事件检测方法

摘要

FIELD: computer equipment.;SUBSTANCE: invention relates to computer engineering. Method for generating a set of convolutions of safe events in which an agent is launched in the operating system of at least one knowingly safe computer device, registering events of at least one type occurring in the operating system of the computer device, where at least the types of events are: start of processes; loading modules; file operations; register operations; detect interceptors installed in the operating system, an event that has occurred in the operating system; register the agent with the detected event and receive from the computer device the context of the specified event; allocate from the received context of the event the signs of the event and form the convolution of the detected event on the basis of the selected features; add convolution to a set of convolutions of safe events.;EFFECT: technical result is to ensure the formation of convolutions of safe events.;45 cl, 5 dwg
机译:技术领域本发明涉及计算机工程。生成一组安全事件卷积的方法,其中在至少一个已知安全的计算机设备的操作系统中启动代理,注册在计算机设备的操作系统中发生的至少一种类型的事件,其中至少事件类型是:流程开始;加载模块;文件操作;注册操作;检测操作系统中安装的拦截器,即操作系统中发生的事件;在检测到的事件中注册代理,并从计算机设备接收指定事件的上下文;从接收到的事件上下文中分配事件的迹象,并根据所选特征形成检测到的事件的卷积;效果:技术结果是确保安全事件的卷积的形成。; 45 cl,5 dwg

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号