首页>
外国专利>
BACKWARDS RESEARCHING ACTIVITY INDICATIVE OF PESTWARE
BACKWARDS RESEARCHING ACTIVITY INDICATIVE OF PESTWARE
展开▼
机译:有害生物研究指标的落后
展开▼
页面导航
摘要
著录项
相似文献
摘要
A system and method for researching an identity of a source of activity that is indicative of pestware is described. In one embodiment the method comprises monitoring, using a kernel-mode driver, API call activity on the computer; storing information related to the API call activity in a log; analyzing, heuristically, the API call activity to determine whether one or more weighted factors associated with the API call activity exceeds a threshold; identifying, based upon the API call activity, a suspected pestware object on the computer; identifying, in response to the identifying the suspected pestware object, a reference to an identity of an externally networked source of the suspected pestware object; and reporting the identity of the externally networked source to an externally networked pestware research entity.
展开▼