首页> 外国专利> AUXILIARY METHOD FOR INVESTIGATING LURKING PROGRAM INCIDENTS

AUXILIARY METHOD FOR INVESTIGATING LURKING PROGRAM INCIDENTS

机译:调查偷渡活动的辅助方法

摘要

An auxiliary method for investigating lurking program incidents is disclosed. The method is to keep monitoring a plurality of processes run by a computer system and save process-invoking relationship data of each process being monitored when the process is created and terminated. Simultaneously, a system registry database of the computer system is also monitored and autostart-registered data of the programs is saved. Then correlate the process-invoking relationship data to the autostart-registered data for generating and saving process-invoking relationship log so as to extract and save high-level crucial clues of suspicious lurking programs. By the present method, only a little amount of high level crucial clues and process-invoking relationship log is collected and a few system resources is consumed for providing clear evidence that is helpful to investigation of lurking program incidents. Thus cost of time and labor for collecting and analyzing large amount of low-level logs is saved.
机译:公开了一种用于调查潜伏节目事件的辅助方法。该方法是保持监视由计算机系统运行的多个进程,并在创建和终止进程时保存正在监视的每个进程的进程调用关系数据。同时,还监视计算机系统的系统注册表数据库,并保存程序的自动启动注册数据。然后将流程调用关系数据与自动启动注册数据相关联,以生成并保存流程调用关系日志,以提取并保存可疑潜伏程序的高级关键线索。通过本方法,仅收集了少量的高级关键线索和过程调用关系日志,并且消耗了一些系统资源来提供有助于研究潜伏程序事件的清晰证据。因此,节省了用于收集和分析大量低级日志的时间和人力成本。

著录项

  • 公开/公告号US2009144821A1

    专利类型

  • 公开/公告日2009-06-04

    原文格式PDF

  • 申请/专利权人 HSING-KUO WONG;YI-BIN LU;

    申请/专利号US20070948168

  • 发明设计人 HSING-KUO WONG;YI-BIN LU;

    申请日2007-11-30

  • 分类号G06F11/30;

  • 国家 US

  • 入库时间 2022-08-21 19:31:45

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号