首页> 外国专利> SIGNATURE-INDEPENDENT, SYSTEM BEHAVIOR-BASED MALWARE DETECTION

SIGNATURE-INDEPENDENT, SYSTEM BEHAVIOR-BASED MALWARE DETECTION

机译:独立于信号的,基于系统行为的恶意软件检测

摘要

A method, system, and computer program product for detecting malware based upon system behavior. At least one process expected to be active is identified for a current mode of operation of a processing system comprising one or more resources. An expected activity level of the one or more resources of the processing system is calculated based upon the current mode of operation and the at least one process expected to be active. An actual activity level of the plurality of resources is determined. If a deviation is detected between the expected activity level and the actual activity level, a source of unexpected activity is identified as a potential cause of the deviation. Policy guidelines are used to determine whether the unexpected activity is legitimate. If the unexpected activity is not legitimate, the source of the unexpected activity is classified as malware.
机译:一种用于基于系统行为来检测恶意软件的方法,系统和计算机程序产品。对于包括一个或多个资源的处理系统的当前操作模式,识别至少预期被激活的过程。基于当前操作模式和至少一个预期活动的过程,计算处理系统的一个或多个资源的预期活动水平。确定多个资源的实际活动水平。如果在预期活动水平和实际活动水平之间检测到偏差,则将意外活动的来源标识为偏差的潜在原因。使用策略准则来确定意外活动是否合法。如果意外活动不合法,则意外活动的来源归为恶意软件。

著录项

  • 公开/公告号EP2656269A4

    专利类型

  • 公开/公告日2014-11-26

    原文格式PDF

  • 申请/专利权人 INTEL CORPORATION;

    申请/专利号EP20110850336

  • 发明设计人 POORNACHANDRAN RAJESH;AISSI SELIM;

    申请日2011-12-13

  • 分类号G06F21/20;

  • 国家 EP

  • 入库时间 2022-08-21 15:06:36

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号