首页> 外国专利> ACTIVITY MONITORING SYSTEM OF MALICIOUS CODE TO CREATE A CHILD PROCESS AND ACTIVITY MONITORING METHOD THEREOF

ACTIVITY MONITORING SYSTEM OF MALICIOUS CODE TO CREATE A CHILD PROCESS AND ACTIVITY MONITORING METHOD THEREOF

机译:创建儿童过程的恶意代码活动监视系统及其活动监视方法

摘要

PURPOSE: A malicious code action monitoring system and a method thereof are provided to generate a child process capable of extracting a malicious code by using action information including a child process which the malicious code additionally executes. CONSTITUTION: An action information storing module(200) stores action information which is monitored in a kernel filter driver on a first table. A malicious code action extracting module(300) extracts the action which is matched with a process of the malicious code. A child process information extracting module(400) extracts process information of the child process.
机译:目的:提供一种恶意代码动作监视系统及其方法,以生成能够通过使用包括恶意代码另外执行的子进程的动作信息来提取恶意代码的子进程。构成:动作信息存储模块(200)存储在第一表的内核过滤器驱动程序中监视的动作信息。恶意代码动作提取模块(300)提取与恶意代码的过程匹配的动作。子进程信息提取模块(400)提取子进程的进程信息。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号