首页> 外国专利> Method using kernel mode assistance for the detection and removal of threats which are actively preventing detection and removal from a running system

Method using kernel mode assistance for the detection and removal of threats which are actively preventing detection and removal from a running system

机译:使用内核模式辅助来检测和消除威胁的方法,这些威胁正在积极阻止从运行中的系统进行检测和消除

摘要

A user mode application component invokes the assistance of a kernel mode driver component to detect and/or remediate malicious code on a computer system. The user mode application may include code that detects, for example, spyware and computer viruses, from user mode and when appropriate takes protective action when malicious code is detected. In one aspect, when the user mode application is unable to perform a selected operation in attempting to detect and/or take protective action, the user mode application invokes a kernel mode driver for assistance. The kernel mode driver assists user mode application in detecting malicious code and/or taking protective action by enabling or otherwise performing a selected operation for the user mode application.
机译:用户模式应用程序组件调用内核模式驱动程序组件的协助,以检测和/或补救计算机系统上的恶意代码。用户模式应用程序可以包括从用户模式检测例如间谍软件和计算机病毒的代码,并在检测到恶意代码时在适当时采取保护措施。一方面,当用户模式应用程序在尝试检测和/或采取保护性操作时无法执行选定的操作时,用户模式应用程序将调用内核模式驱动程序以寻求帮助。内核模式驱动程序通过启用或以其他方式为用户模式应用程序执行选定的操作,协助用户模式应用程序检测恶意代码和/或采取保护措施。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号