首页> 外国专利> System and method for dynamically detecting computer viruses through associative behavioral analysis of runtime state

System and method for dynamically detecting computer viruses through associative behavioral analysis of runtime state

机译:通过运行时状态的关联行为分析来动态检测计算机病毒的系统和方法

摘要

A system and a method for dynamically detecting computer viruses through associative behavioral analysis of runtime state are described. A group of monitored events is defined. Each monitored event includes a set of one or more actions defined within an object. Each action is performed by one or more applications executing within a defined computing environment. The runtime state within the defined computing environment is continuously monitored for an occurrence of any one of the monitored events in the group. The sequence of the execution of the monitored events is tracked for each of the applications. Each occurrence of a specific event sequence characteristic of computer virus behavior and the application that performed the specific event sequence, are identified. A histogram describing the specific event sequence occurrence for each of the applications is created. Repetitions of the histogram associated with at least one object are identified.
机译:描述了一种通过运行时状态的关联行为分析来动态检测计算机病毒的系统和方法。定义了一组受监视的事件。每个受监视的事件都包含在一个对象内定义的一组一个或多个动作。每个动作由在定义的计算环境中执行的一个或多个应用程序执行。连续监视定义的计算环境内的运行时状态,以查看组中任何受监视事件的发生。为每个应用程序跟踪受监视事件的执行顺序。确定计算机病毒行为特征的特定事件序列的每次出现以及执行特定事件序列的应用程序。创建描述每个应用程序的特定事件序列发生的直方图。识别与至少一个对象相关联的直方图的重复。

著录项

  • 公开/公告号US6973577B1

    专利类型

  • 公开/公告日2005-12-06

    原文格式PDF

  • 申请/专利权人 VICTOR KOUZNETSOV;

    申请/专利号US20000579810

  • 发明设计人 VICTOR KOUZNETSOV;

    申请日2000-05-26

  • 分类号G06F11/30;G06F12/14;H04L9/00;H04L9/32;

  • 国家 US

  • 入库时间 2022-08-21 21:40:32

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号