首页> 外国专利> FORENSIC ANALYSIS OF COMPUTING ACTIVITY AND MALWARE DETECTION USING AN EVENT GRAPH

FORENSIC ANALYSIS OF COMPUTING ACTIVITY AND MALWARE DETECTION USING AN EVENT GRAPH

机译:使用事件图进行计算活动和恶意软件检测的法医分析

摘要

A data recorder stores endpoint activity on an ongoing basis as sequences ofevents that causally relate computerobjects such as processes and files. When a security event is detected, anevent graph may be generated based on these causalrelationships among the computing objects. For a root cause analysis, theevent graph may be traversed in a reverse order from the point ofan identified security event (e.g., a malware detection event) to precedingcomputing objects, while applying one or more causeidentification rules to identify a root cause of the security event. Once aroot cause is identified, the event graph may be traversedforward from the root cause to identify other computing objects that arepotentially compromised by the root cause. Further, patternswithin the event graph can be used to detect the presence of malware on theendpoint.
机译:数据记录器按以下顺序连续存储端点活动:与计算机有因果关系的事件对象,例如进程和文件。当检测到安全事件时,可以基于这些因果关系生成事件图计算对象之间的关系。对于根本原因分析,事件图可以从点开始以相反的顺序遍历之前的已识别安全事件(例如,恶意软件检测事件)计算对象,同时应用一个或多个原因识别规则以识别安全事件的根本原因。一旦确定根本原因,可能会遍历事件图从根本原因出发确定其他计算对象根本原因可能会损害它。此外,模式事件图中的图表可用于检测恶意软件在端点。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号