首页> 外国专利> BEHAVIORAL ANALYTICS DRIVEN HOST-BASED MALICIOUS BEHAVIOR AND DATA EXFILTRATION DISRUPTION

BEHAVIORAL ANALYTICS DRIVEN HOST-BASED MALICIOUS BEHAVIOR AND DATA EXFILTRATION DISRUPTION

机译:行为分析驱动的基于主机的恶意行为和数据抽取失真

摘要

A system and method detects the existence of malicious software on a local host by analysis of software process behavior including user input events and system events. A user validation engine provides user notification. In-VM operating system monitors capture events handled by the OS, capture user input from the HMI devices, and capture system events from applications executed by the processor at hardware, kernel and/or API levels. The In-VM operating system monitors also pass captured user input and system events to the user validation engine for analysis. The user validation engine identifies legitimate user events as those that move from the hardware level upward to pre-selected applications, identifies illegitimate user events as those that start at the kernel and/or API levels, and approves communication for legitimate events while denying communication for illegitimate events.
机译:一种系统和方法通过分析包括用户输入事件和系统事件的软件过程行为来检测本地主机上恶意软件的存在。用户验证引擎提供用户通知。 VM中的操作系统监视捕获由OS处理的事件,捕获来自HMI设备的用户输入以及捕获由处理器在硬件,内核和/或API级别执行的应用程序的系统事件。 VM中的操作系统监视器还将捕获的用户输入和系统事件传递到用户验证引擎进行分析。用户验证引擎将合法的用户事件标识为从硬件级别向上移动到预选应用程序的事件,将非法的用户事件标识为从内核和/或API级别开始的事件,并批准合法事件的通信,同时拒绝针对以下事件的通信非法事件。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号