Invention Grant
US08627458B2 Detecting malicious computer program activity using external program calls with dynamic rule sets
有权
使用具有动态规则集的外部程序调用来检测恶意计算机程序活动
- Patent Title: Detecting malicious computer program activity using external program calls with dynamic rule sets
- Patent Title (中): 使用具有动态规则集的外部程序调用来检测恶意计算机程序活动
-
Application No.: US10755450Application Date: 2004-01-13
-
Publication No.: US08627458B2Publication Date: 2014-01-07
- Inventor: Igor Garrievich Muttik
- Applicant: Igor Garrievich Muttik
- Applicant Address: US CA Santa Clara
- Assignee: McAfee, Inc.
- Current Assignee: McAfee, Inc.
- Current Assignee Address: US CA Santa Clara
- Agency: Patent Capital Group
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A stream 14 of external computer program calls made from an application program 2 to an operating system 4 is logged by an anti-malware layer 8. This stream 14 is examined for a primary set XYZ of external program calls known to be associated with malicious computer program activity. When such a primary set XYZ of external computer program calls is identified, the malicious activity is blocked and the logged stream 14 is examined to determine one or more secondary sets of external program calls which are now added to the set of rules 10 against which the logged stream 14 of external program calls is tested. In this way the set of rules 10 is dynamically adapted so as to more rapidly and proactively identify malicious computer program activity.
Public/Granted literature
- US20050154900A1 Detecting malicious computer program activity using external program calls with dynamic rule sets Public/Granted day:2005-07-14
Information query