首页> 外国专利> Malware detection efficacy by identifying installation and uninstallation scenarios

Malware detection efficacy by identifying installation and uninstallation scenarios

机译:通过确定安装和卸载方案来检测恶意软件

摘要

The launch of an installer or uninstaller is detected. A process lineage tree is created representing the detected launched installer/uninstaller process, and all processes launched directly and indirectly thereby. The detected installer/uninstaller process is represented by the root node in the process lineage tree. Launches of child processes by the installer/uninstaller process and by any subsequently launched child processes are detected. The launched child processes are represented by child nodes in the tree. As long as the installer/uninstaller process represented by the root node in the tree is running, the processes represented by nodes in tree are exempted from anti-malware analysis. The termination of the installer/uninstaller process is detected, after which the processes represented by nodes in the process lineage tree are no longer exempted from anti-malware analysis.
机译:检测到安装程序或卸载程序的启动。将创建一个进程沿袭树,代表检测到的已启动的安装程序/卸载程序进程,并由此直接或间接启动所有进程。检测到的安装程序/卸载程序进程由进程沿袭树中的根节点表示。检测安装程序/卸载程序进程和随后启动的任何子进程启动的子进程。启动的子进程由树中的子节点表示。只要树中的根节点所代表的安装程序/卸载程序正在运行,树中的节点所代表的进程就可以免于反恶意软件分析。检测到安装程序/卸载程序进程的终止,此后,进程血统树中的节点所代表的进程将不再免于反恶意软件分析。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号