首页> 外国专利> Identifying malicious applications by statistical analysis of currently running programs and network connections

Identifying malicious applications by statistical analysis of currently running programs and network connections

机译:通过对当前正在运行的程序和网络连接进行统计分析来识别恶意应用程序

摘要

A security application running on a computer system generates an application list indicating applications that are currently running. The system identifies network addresses meeting established criteria, such as entries in an IP whitelist or a database of malicious servers. The system then determines whether connections to those addresses have been made within a certain timeframe, and provides the application list LAPP and identified addresses LDOMHITS to another application 712, which may be on an external server 710 receiving information from multiple clients 100, 720, 722, 724. A statistical analysis is then performed to determine which of the applications in the list provided the connection to the suspect address. The analysing application may provide instruction to the system to kill the identified malware. If the operating platform restricts access to these details, the application list can be inferred from installed applications, and the network connections from DNS cache or routing table queries. This allows the detection and elimination of hazardous programs even in systems with restrictive security models.
机译:在计算机系统上运行的安全应用程序会生成一个应用程序列表,指示当前正在运行的应用程序。系统会识别满足既定标准的网络地址,例如IP白名单中的条目或恶意服务器的数据库中的条目。然后,系统确定是否已在特定时间范围内建立了与那些地址的连接,并将应​​用程序列表LAPP和已标识的地址LDOMHITS提供给另一个应用程序712,该应用程序可以位于外部服务器710上,该服务器从多个客户端100、720、722接收信息。 724。然后执行统计分析以确定列表中的哪个应用程序提供了与可疑地址的连接。分析应用可以向系统提供指令以杀死所识别的恶意软件。如果操作平台限制对这些详细信息的访问,则可以从已安装的应用程序中推断应用程序列表,并可以从DNS缓存或路由表查询中推断出网络连接。即使在具有严格安全模型的系统中,这也可以检测和消除危险程序。

著录项

  • 公开/公告号GB2508174A

    专利类型

  • 公开/公告日2014-05-28

    原文格式PDF

  • 申请/专利权人 F-SECURE CORPORATION;

    申请/专利号GB20120021006

  • 发明设计人 ANTTI TIKKANEN;DAAVID HENTUNEN;

    申请日2012-11-22

  • 分类号G06F21/56;G06F11/34;

  • 国家 GB

  • 入库时间 2022-08-21 15:35:46

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号