首页> 外国专利> Systems and methods for using reputation data to detect shared-object-based security threats

Systems and methods for using reputation data to detect shared-object-based security threats

机译:使用信誉数据检测基于共享对象的安全威胁的系统和方法

摘要

Computer-implemented methods and systems for using reputation data to detect shared-object-based security threats are disclosed. In one example, an exemplary method for performing such a task may comprise: 1) identifying a process, 2) identifying an executable file associated with the process, 3) identifying at least one shared object loaded by the process, 4) obtaining reputation data for both the executable file and the shared object from a reputation service, 5) determining that the shared object represents a potential security risk by comparing the reputation data for the executable file with the reputation data for the shared object and determining that the reputation data for the shared object is significantly different from the reputation data for the executable file, and then 6) performing a security operation on the shared object. Corresponding server-side methods and systems for identifying malicious shared objects based on reputation data are also disclosed.
机译:公开了用于使用信誉数据来检测基于共享对象的安全威胁的计算机实现的方法和系统。在一个示例中,用于执行这样的任务的示例性方法可以包括:1)识别进程,2)识别与该进程相关联的可执行文件,3)识别由该进程加载的至少一个共享对象,4)获取信誉数据对于信誉文件服务中的可执行文件和共享对象,5)通过将可执行文件的信誉数据与共享对象的信誉数据进行比较,并确定信誉数据来确定共享对象是否存在潜在的安全风险。共享对象与可执行文件的信誉数据明显不同,然后6)对共享对象执行安全操作。还公开了用于基于信誉数据来识别恶意共享对象的对应的服务器端方法和系统。

著录项

  • 公开/公告号US8225406B1

    专利类型

  • 公开/公告日2012-07-17

    原文格式PDF

  • 申请/专利权人 CAREY S. NACHENBERG;

    申请/专利号US20090415834

  • 发明设计人 CAREY S. NACHENBERG;

    申请日2009-03-31

  • 分类号G06F11/00;

  • 国家 US

  • 入库时间 2022-08-21 17:29:52

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号