首页> 外国专利> METHODS AND SYSTEMS FOR IDENTIFYING MALWARE THROUGH DIFFERENCES IN CLOUD VS. CLIENT BEHAVIOR

METHODS AND SYSTEMS FOR IDENTIFYING MALWARE THROUGH DIFFERENCES IN CLOUD VS. CLIENT BEHAVIOR

机译:通过云中的差异识别恶意软件的方法和系统。客户行为

摘要

A computing device may be configured to work in conjunction with another component (e.g., a server) to better determine whether a software application is benign or non-benign. This may be accomplished via the server performing static and/or dynamic analysis operations, generating a behavior information structure that describes or characterizes the range of correct or expected behaviors of the software application, and sending the behavior information structure to a computing device. The computing device may compare the received behavior information structure to a locally generated behavior information structure to determining whether the observed behavior of the software application differs or deviates from the expected behavior of the software application or whether the observed behavior is within the range of expected behaviors. The computing device may increase its level of security/scrutiny when the behavior information structure does not match the local behavior information structure.
机译:计算设备可以被配置为与另一组件(例如,服务器)结合工作,以更好地确定软件应用是良性的还是非良性的。这可以通过服务器执行静态和/或动态分析操作,生成描述或表征软件应用程序的正确或预期行为的范围的行为信息结构,以及将行为信息结构发送到计算设备来实现。计算设备可以将接收到的行为信息结构与本地生成的行为信息结构进行比较,以确定所观察到的软件应用程序的行为是否不同于或偏离软件应用程序的预期行为,或者所观察到的行为是否在预期行为的范围内。当行为信息结构与本地行为信息结构不匹配时,计算设备可以提高其安全性/审查级别。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号