首页> 外国专利> NETWORK-TYPE VIRUS ACTIVITY DETECTION PROGRAM, PROCESSING METHOD AND SYSTEM

NETWORK-TYPE VIRUS ACTIVITY DETECTION PROGRAM, PROCESSING METHOD AND SYSTEM

机译:网络型病毒活动检测程序,处理方法及系统

摘要

PROBLEM TO BE SOLVED: To detect the activity of a network-type virus on a PC under zero-day attack without use of a signature, thereby preventing the spread of infection.;SOLUTION: A monitoring part 11 monitors outbound communications using a network interface 3. A process specifying part 12 specifies a process 2X that caused communication. A process-tree acquisition part 13 outputs process-tree information by which a process preceding the process 2X is specified. A determining part 14 refers to a corruption rule file 18 that defines corruption processes by combining the process that caused communication and the process preceding it, and determines whether or not the process 2X is corrupt according to communication information, process information and the process-tree information. A process stopping part 15 stops the process 2X determined to be corrupt. A notification part 16 notifies the user of the stop of the process 2X.;COPYRIGHT: (C)2006,JPO&NCIPI
机译:解决的问题:在零日攻击下无需使用签名即可检测PC上网络型病毒的活动,从而防止感染的传播。;解决方案:监视部分11使用网络接口监视出站通信。 3.处理确定部12确定引起通信的处理2X。处理树获取部13输出处理树信息,通过该处理树信息指定处理2X之前的处理。确定部14参考破坏规则文件18,该破坏规则文件18通过组合引起通信的过程和在其之前的过程来定义破坏过程,并根据通信信息,过程信息和过程树来确定过程2X是否被破坏。信息。处理停止部15使判定为破坏的处理2X停止。通知部分16将处理2X的停止通知用户。版权所有:(C)2006,JPO&NCIPI

著录项

  • 公开/公告号JP2006119754A

    专利类型

  • 公开/公告日2006-05-11

    原文格式PDF

  • 申请/专利权人 FUJITSU LTD;

    申请/专利号JP20040304711

  • 申请日2004-10-19

  • 分类号G06F21/22;

  • 国家 JP

  • 入库时间 2022-08-21 21:56:25

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号