首页> 外国专利> System and method for strategic anti-malware monitoring

System and method for strategic anti-malware monitoring

机译:战略反恶意软件监控系统和方法

摘要

The system and method described herein may leverage active network scanning and passive network monitoring to provide strategic anti-malware monitoring in a network. In particular, the system and method described herein may remotely connect to managed hosts in a network to compute hashes or other signatures associated with processes running thereon and suspicious files hosted thereon, wherein the hashes may communicated to a cloud database that aggregates all known virus or malware signatures that various anti-virus vendors have catalogued to detect malware infections without requiring the hosts to have a local or resident anti-virus agent. Furthermore, running processes and file system activity may be monitored in the network to further detect malware infections. Additionally, the network scanning and network monitoring may be used to detect hosts that may potentially be participating in an active botnet or hosting botnet content and audit anti-virus strategies deployed in the network.
机译:这里描述的系统和方法可以利用主动网络扫描和被动网络监视,以在网络中提供战略反恶意软件监视。具体地,本文描述的系统和方法可以远程连接到网络中的受管主机,以计算与在其上运行的进程相关联的哈希或其他签名,其中散列可以传送到聚合所有已知病毒的云数据库或者恶意软件签名,各种反病毒供应商已编目以检测恶意软件感染,而无需主持人具有本地或居民抗病毒剂。此外,可以在网络中监视运行进程和文件系统活动,以进一步检测恶意软件感染。另外,网络扫描和网络监视可用于检测可能潜在地参与活动僵尸网络或托管在网络中部署的僵尸网络内容和审计反病毒策略的主机。

著录项

  • 公开/公告号US11057422B2

    专利类型

  • 公开/公告日2021-07-06

    原文格式PDF

  • 申请/专利权人 TENABLE INC.;

    申请/专利号US202016748533

  • 发明设计人 MARCUS J. RANUM;RON GULA;

    申请日2020-01-21

  • 分类号G06F21/56;H04L29/06;G06F16/903;H04L29/12;H04L29/08;

  • 国家 US

  • 入库时间 2022-08-24 19:43:42

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号