Invention Grant
US07694150B1 System and methods for integration of behavioral and signature based security 有权
整合基于行为和签名的安全性的系统和方法

  • Patent Title: System and methods for integration of behavioral and signature based security
  • Patent Title (中): 整合基于行为和签名的安全性的系统和方法
  • Application No.: US10873734
    Application Date: 2004-06-22
  • Publication No.: US07694150B1
    Publication Date: 2010-04-06
  • Inventor: Alan J. Kirby
  • Applicant: Alan J. Kirby
  • Applicant Address: US CA San Jose
  • Assignee: Cisco Technology, Inc
  • Current Assignee: Cisco Technology, Inc
  • Current Assignee Address: US CA San Jose
  • Main IPC: G06F9/00
  • IPC: G06F9/00
System and methods for integration of behavioral and signature based security
Abstract:
Conventional matching approaches to virus detection are ineffective pending deployment of a signature to match a newly discovered virus. In contrast, a behavioral based (subject) approach addresses the so-called “day zero” problem of object matching approaches. An integrated approach combines the behavioral remedy against unknown transmissions with the signature matching of known harmful transmission to provide the reliability and stability of signature based approaches with the real time responsiveness of the behavioral approach. A behavior monitoring module analyzes actions via behavioral heuristics indicative of actions performed by known harmful transmissions. The behavioral monitoring correlates the actions performed to determine an undesirable object. A signature generator computes a realtime signature on the suspect object. The signature generator accumulates successive realtime signatures in this manner for comparison with subsequent incoming transmissions, thus combining the subject based behavioral aspects of virus detection with the deterministic aspects of the object approach.
Information query
Patent Agency Ranking
0/0