首页> 外国专利> PATH-BASED PROGRAM LINEAGE INFERENCE ANALYSIS

PATH-BASED PROGRAM LINEAGE INFERENCE ANALYSIS

机译:基于路径的程序谱系推断分析

摘要

Systems and methods are disclosed for securing an enterprise environment by detecting suspicious software. A global program lineage graph is constructed. Construction of the global program lineage graph includes creating a node for each version of a program having been installed on a set of user machines. Additionally, at least two nodes are linked with a directional edge. For each version of the program, a prevalence number of the set of user machines on which each version of the program had been installed is determined; and the prevalence number is recorded to the metadata associated with the respective node. Anomalous behavior is identified based on structures formed by the at least two nodes and associated directional edge in the global program lineage graph. An alarm is displayed on a graphical user interface for each suspicious software based on the identified anomalous behavior.
机译:公开了用于通过检测可疑软件来保护企业环境的系统和方法。构造了全局程序沿袭图。全局程序沿袭图的构建包括为已安装在一组用户机器上的程序的每个版本创建一个节点。另外,至少两个节点与定向边缘链接。对于该程序的每个版本,确定已安装该程序的每个版本的一组用户计算机的普遍性;并将流行度记录到与各个节点关联的元数据中。基于全局程序沿袭图中至少两个节点和关联的有向边形成的结构来识别异常行为。根据识别出的异常行为,在每个可疑软件的图形用户界面上显示一个警报。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号