首页> 外国专利> DETECTING MALICIOUS ACTIVITY BY ANALYSING THE BEHAVIOUR OF OBJECTS IN A NON-ISOLATED ENVIRONMENT

DETECTING MALICIOUS ACTIVITY BY ANALYSING THE BEHAVIOUR OF OBJECTS IN A NON-ISOLATED ENVIRONMENT

机译:通过分析非隔离环境中对象的行为来检测恶意活动

摘要

The computer-implementable method for detection of malicious activity by analysis of behavior in non-isolated environment, the method comprising: collecting information into at least one event flow using a detection module; transmitting at least one event flow to a computing device, and analyzing, using the computing device, the obtained event flow for a predetermined amount of time, wherein transmitting at least one event from the event flow to input of at least one adapter, depending on the event type, wherein at least one adapter generates its internal event; transmitting at least one internal event to at least one signature module, and checking at least one obtained internal event using at least one signature module according to preset rules, and in case of at least one internal event correspondence to the preset rules, creating at least one internal state marker; transmitting at least one internal state marker to input of a malicious activity decision module, wherein, if at least one internal state marker total weight or probability of at least one internal state marker maliciousness exceeds a preset value, detecting the malicious activity using the decision module on the basis of difference from the allowed behavior; creating a report on suspicious activity.
机译:一种用于通过分析非隔离环境中的行为来检测恶意活动的计算机可实现方法,该方法包括:使用检测模块将信息收集到至少一个事件流中;将至少一个事件流发送到计算设备,并使用该计算设备在预定的时间量内分析所获得的事件流,其中根据事件类型将至少一个事件从事件流发送到至少一个适配器的输入,其中至少一个适配器生成其内部事件;向至少一个签名模块发送至少一个内部事件,并根据预设规则使用至少一个签名模块检查至少一个获得的内部事件,并且在至少一个内部事件与预设规则对应的情况下,创建至少一个内部状态标记;将至少一个内部状态标记发送到恶意活动决策模块的输入端,其中,如果至少一个内部状态标记的总权重或至少一个内部状态标记恶意性的概率超过预设值,则基于与允许的行为的差异,使用决策模块检测恶意活动;创建可疑活动的报告。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号