首页> 外国专利> Method and system for detection of previously unknown malware components

Method and system for detection of previously unknown malware components

机译:用于检测先前未知的恶意软件组件的方法和系统

摘要

A system, method, and computer program product for identifying malware components on a computer, including detecting an attempt to create or modify an executable file or an attempt to write to a system registry; logging the attempt as an auditable event; performing a malware check on executable files of the computer; if malware is detected on the computer, identifying all other files created or modified during the auditable event, and all other processes related to the auditable event; terminating the processes related to the auditable event; deleting or quarantining the executable files created or modified during the auditable event; and if the deleted executable files include any system files, restoring the system files from a trusted backup. Optionally, all files and processes having a parent-child relationship to a known malware component or known infected file are identified. A log of auditable events is maintained, and is recoverable after system reboot.
机译:一种用于识别计算机上的恶意软件组件的系统,方法和计算机程序产品,包括检测创建或修改可执行文件的尝试或写入系统注册表的尝试;将尝试记录为可审核事件;对计算机的可执行文件进行恶意软件检查;如果在计算机上检测到恶意软件,则标识在可审核事件期间创建或修改的所有其他文件,以及与可审核事件有关的所有其他进程;终止与可审核事件有关的流程;删除或隔离在可审核事件期间创建或修改的可执行文件;如果删除的可执行文件包括任何系统文件,请从受信任的备份中还原系统文件。可选地,标识与已知恶意软件组件或已知受感染文件具有父子关系的所有文件和进程。保留可审核事件的日志,并且该日志可在系统重新引导后恢复。

著录项

  • 公开/公告号US8104090B1

    专利类型

  • 公开/公告日2012-01-24

    原文格式PDF

  • 申请/专利权人 MIKHAIL A. PAVLYUSHCHIK;

    申请/专利号US20080335327

  • 发明设计人 MIKHAIL A. PAVLYUSHCHIK;

    申请日2008-12-15

  • 分类号G06F21/00;

  • 国家 US

  • 入库时间 2022-08-21 17:26:24

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号