首页> 外国专利> MALICIOUS SOFTWARE IDENTIFICATION INTEGRATING BEHAVIORAL ANALYTICS AND HARDWARE EVENTS

MALICIOUS SOFTWARE IDENTIFICATION INTEGRATING BEHAVIORAL ANALYTICS AND HARDWARE EVENTS

机译:集成了行为分析和硬件事件的恶意软件标识

摘要

A security system and method secures and responds to security threats in a computer having a CPU, a Kernel/OS, and software applications. A low-level data collector intercepts a selection of first tier calls between the CPU and Kernel/OS, and stores associated first tier call IDs. A Kernel module intercepts a selection of second tier calls between applications and the Kernel/OS, and stores associated second tier call IDs. An Analytic Engine maps the stored first and second tier call IDs to a rulebase containing patterns of security threats, to generate a threat analysis, and then responds to the threat analysis. The Analytic Engine enlarges or contracts the selection of first and second tier calls to increase or decrease specificity of the threat analysis. A Management Module generates user interfaces accessible remotely by a user device, to update the rulebase and configure the low-level collector, the Kernel module, and the Analytic Engine.
机译:安全系统和方法保护具有CPU,内核/ OS和软件应用程序的计算机中的安全威胁并对其作出响应。低级数据收集器拦截CPU和内核/ OS之间的第一层调用选择,并存储关联的第一层调用ID。内核模块拦截应用程序和内核/ OS之间的第二层调用选择,并存储关联的第二层调用ID。解析引擎将存储的第一层和第二层呼叫ID映射到包含安全威胁模式的规则库,以生成威胁分析,然后对威胁分析做出响应。分析引擎扩大或缩小对第一层和第二层调用的选择,以增加或减少威胁分析的特异性。管理模块生成可由用户设备远程访问的用户界面,以更新规则库并配置低级收集器,内核模块和分析引擎。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号