Invention Grant
- Patent Title: Process profiling for behavioral anomaly detection
- Patent Title (中): 行为异常检测的过程分析
-
Application No.: US11674934Application Date: 2007-02-14
-
Publication No.: US08171545B1Publication Date: 2012-05-01
- Inventor: Shaun Cooley , Bruce McCorkendale
- Applicant: Shaun Cooley , Bruce McCorkendale
- Applicant Address: US CA Mountain View
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Mountain View
- Agency: Brill Law Office
- Agent Jeffrey Brill
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
An anomalous process behavior manager uses statistical information concerning running processes to detect and manage process behavioral anomalies. The anomalous process behavior manager collects per process statistical data over time, such as resource allocation statistics and user interaction statistics. Current collected statistical data is analyzed against corresponding historical statistical data to determine whether processes are behaving in expected ways relative to past performance. Appropriate corrective steps are taken when it is determined that a process is behaving anomalously. For example, the process's blocking exclusions can be revoked, the process can be uninstalled, the process and/or the computer can be scanned for malicious code, the user can be alerted and/or relevant information can be shared with other parties.
Information query