首页> 外国专利> Method and system for identifying malware through differences between cloud vs. client behavior

Method and system for identifying malware through differences between cloud vs. client behavior

机译:通过云与客户端行为之间的差异识别恶意软件的方法和系统

摘要

Computing devices may be configured to work with other components (e.g., servers) to better determine whether the software application is benign or irrational.This means that the server executes a static and / or dynamic analysis operation to describe or characterize the correct or expected behavior range of the software application, or generate a behavioral information structure, and compute the behavior information structure Can be achieved via sending to a device.The computing device compares the received behavior information structure with the locally generated behavior information structure, and the observed behavior of the software application is different from the expected behavior of the software application Or whether or not the observed behavior is within the expected behavior is determined.The computing device can increase the level of security / scrutiny when the behavioral information structure does not match the local behavior information structure.
机译:计算设备可以配置为与其他组件(例如服务器)一起使用,以更好地确定软件应用程序是良性还是不合理。这意味着服务器执行静态和/或动态分析操作,以描述或表征正确或预期的特性软件应用程序的行为范围,或生成行为信息结构,并计算行为信息结构,可以通过发送到设备来实现。计算设备将接收到的行为信息结构与本地生成的行为信息结构进行比较,并观察到的行为软件应用程序的行为与软件应用程序的预期行为不同,或者确定观察到的行为是否在预期行为之内。当行为信息结构与应用程序的行为信息结构不匹配时,计算设备可以提高安全级别本地行为信息结构。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号