首页> 外国专利> Malware detection via network information flow theories

Malware detection via network information flow theories

机译:通过网络信息流理论检测恶意软件

摘要

Access is obtained to a plurality of information flow theories for a plurality of malicious programs. The information flow theories include differences in information flows between the malicious programs, executing in a controlled environment, and information flows of known benign programs. Execution of a suspicious program is monitored by comparing runtime behavior of the suspicious program to the plurality of information flow theories. An alarm is output if the runtime behavior of the suspicious program matches at least one of the plurality of information flow theories.
机译:获得对多个恶意程序的多个信息流理论的访问。信息流理论包括恶意程序之间的信息流,在受控环境中执行的信息流以及已知的良性程序的信息流之间的差异。通过将可疑程序的运行时行为与多个信息流理论进行比较,来监控可疑程序的执行。如果可疑程序的运行时行为与多种信息流理论中的至少一种相匹配,则输出警报。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号