Invention Grant
- Patent Title: Behavioral-based host intrusion prevention system
- Patent Title (中): 基于行为的主机入侵防御系统
-
Application No.: US12506749Application Date: 2009-07-21
-
Publication No.: US08776218B2Publication Date: 2014-07-08
- Inventor: Clifford C. Wright
- Applicant: Clifford C. Wright
- Applicant Address: GB Abingdon Oxfordshire
- Assignee: Sophos Limited
- Current Assignee: Sophos Limited
- Current Assignee Address: GB Abingdon Oxfordshire
- Agency: Strategic Patents, P.C.
- Main IPC: G06F11/00
- IPC: G06F11/00

Abstract:
In embodiments of the present invention improved capabilities are described for behavioral-based threat detection. An executing computer process is monitored for an indication of malicious behavior, wherein the indication of the malicious behavior is a result of comparing an operation with a predetermined behavior, referred to as a gene. A plurality of malicious behavior indications observed for the executing process are compared to a predetermined collection of malicious behaviors, referred to as a phenotype, which comprises a grouping of specific genes that are typically present in a type of malicious code. Upon matching the malicious behavior indications with a phenotype, an action may be caused, where the action is based on a prediction that the executing computer process is the type of malicious code as indicated by the phenotype. Related user interfaces, applications, and computer program products are disclosed.
Public/Granted literature
- US20110023118A1 BEHAVIORAL-BASED HOST INTRUSION PREVENTION SYSTEM Public/Granted day:2011-01-27
Information query