首页>
外国专利>
AUXILIARY METHOD FOR INVESTIGATING LURKING PROGRAM INCIDENTS
AUXILIARY METHOD FOR INVESTIGATING LURKING PROGRAM INCIDENTS
展开▼
机译:调查偷渡活动的辅助方法
展开▼
页面导航
摘要
著录项
相似文献
摘要
An auxiliary method for investigating lurking program incidents is disclosed. The method is to keep monitoring a plurality of processes run by a computer system and save process-invoking relationship data of each process being monitored when the process is created and terminated. Simultaneously, a system registry database of the computer system is also monitored and autostart-registered data of the programs is saved. Then correlate the process-invoking relationship data to the autostart-registered data for generating and saving process-invoking relationship log so as to extract and save high-level crucial clues of suspicious lurking programs. By the present method, only a little amount of high level crucial clues and process-invoking relationship log is collected and a few system resources is consumed for providing clear evidence that is helpful to investigation of lurking program incidents. Thus cost of time and labor for collecting and analyzing large amount of low-level logs is saved.
展开▼