首页> 外国专利> Detecting auto-start malware by checking its aggressive load point behaviors

Detecting auto-start malware by checking its aggressive load point behaviors

机译:通过检查其激进的负载点行为来检测自动启动的恶意软件

摘要

Program behaviors concerning load points are monitored, and a specific program attempting to actively maintain a previously set value of a specific load point is detected. In response, the specific program is adjudicated to be malware, and one or more actions are performed to protect the computer. The monitored behavior can be write operations targeting load points. In this scenario, the behavior indicating that a program is malware can comprise performing a requisite number of write operations to a load point within a requisite time period. The monitored behavior can also be altering load point values, and monitoring the results. The altering of load points can comprise removing values specifying programs to run, and/or changing names of programs. Detecting that a specific altered load point value has been automatically reset within a requisite time period to run the specific program upon start-up indicates that the program is malware.
机译:监视与负载点有关的程序行为,并检测试图主动保持特定负载点的先前设置值的特定程序。作为响应,该特定程序被裁定为恶意软件,并执行一项或多项操作来保护计算机。监视的行为可以是针对负载点的写操作。在这种情况下,指示程序是恶意软件的行为可以包括在必要的时间段内执行对加载点的必要数量的写操作。监视的行为还可以是更改负载点值并监视结果。加载点的改变可以包括去除指定要运行的程序的值,和/或改变程序的名称。如果在启动后运行特定程序的必要时间段内检测到已更改的特定加载点值已自动重置,则表明该程序为恶意软件。

著录项

  • 公开/公告号US9330260B1

    专利类型

  • 公开/公告日2016-05-03

    原文格式PDF

  • 申请/专利权人 SYMANTEC CORPORATION;

    申请/专利号US201313951226

  • 发明设计人 FANGLU GUO;

    申请日2013-07-25

  • 分类号H04L29/00;G06F21/56;

  • 国家 US

  • 入库时间 2022-08-21 14:29:20

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号