Invention Grant
US08627458B2 Detecting malicious computer program activity using external program calls with dynamic rule sets 有权
使用具有动态规则集的外部程序调用来检测恶意计算机程序活动

  • Patent Title: Detecting malicious computer program activity using external program calls with dynamic rule sets
  • Patent Title (中): 使用具有动态规则集的外部程序调用来检测恶意计算机程序活动
  • Application No.: US10755450
    Application Date: 2004-01-13
  • Publication No.: US08627458B2
    Publication Date: 2014-01-07
  • Inventor: Igor Garrievich Muttik
  • Applicant: Igor Garrievich Muttik
  • Applicant Address: US CA Santa Clara
  • Assignee: McAfee, Inc.
  • Current Assignee: McAfee, Inc.
  • Current Assignee Address: US CA Santa Clara
  • Agency: Patent Capital Group
  • Main IPC: H04L29/06
  • IPC: H04L29/06
Detecting malicious computer program activity using external program calls with dynamic rule sets
Abstract:
A stream 14 of external computer program calls made from an application program 2 to an operating system 4 is logged by an anti-malware layer 8. This stream 14 is examined for a primary set XYZ of external program calls known to be associated with malicious computer program activity. When such a primary set XYZ of external computer program calls is identified, the malicious activity is blocked and the logged stream 14 is examined to determine one or more secondary sets of external program calls which are now added to the set of rules 10 against which the logged stream 14 of external program calls is tested. In this way the set of rules 10 is dynamically adapted so as to more rapidly and proactively identify malicious computer program activity.
Information query
Patent Agency Ranking
0/0