首页> 外国专利> Threat detection through the accumulated detection of threat characteristics

Threat detection through the accumulated detection of threat characteristics

机译:通过累积检测威胁特征进行威胁检测

摘要

Embodiments of the present disclosure provide for improved capabilities in the detection of malware, where malware threats are detected through the accumulated identification of threat characteristics for targeted computer objects. Methods and systems include dynamic threat detection providing a first database that correlates a plurality of threat characteristics to a threat, wherein a presence of the plurality of the threat characteristics confirms a presence of the threat; detecting a change event in a computer run-time process; testing the change event for a presence of one or more of the plurality of characteristics upon detection of the change event; storing a detection of one of the plurality of characteristics in a second database that accumulates detected characteristics for the computer run-time process; and identifying the threat when each one of the plurality of characteristics appears in the second database.
机译:本公开的实施例在恶意软件的检测中提供了改进的能力,其中,通过针对目标计算机对象的威胁特征的累积标识来检测恶意软件威胁。方法和系统包括:动态威胁检测,提供第一数据库,该第一数据库将多个威胁特征与威胁相关联,其中,多个威胁特征的存在确认威胁的存在;在计算机运行时过程中检测更改事件;在检测到变化事件时,检测变化事件是否存在多个特征中的一个或多个;将多个特征之一的检测结果存储在第二数据库中,该数据库为计算机运行过程积累检测到的特征;当多个特征中的每一个出现在第二数据库中时,识别威胁。

著录项

  • 公开/公告号US9104864B2

    专利类型

  • 公开/公告日2015-08-11

    原文格式PDF

  • 申请/专利权人 SOPHOS LIMITED;

    申请/专利号US201213658977

  • 发明设计人 IRENE MICHLIN;CLIFFORD PENTON;

    申请日2012-10-24

  • 分类号G06F21/00;G06F21/55;G06F21/56;H04L29/06;G06F21/60;

  • 国家 US

  • 入库时间 2022-08-21 15:23:06

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号