Invention Grant
US08832835B1 Detecting and remediating malware dropped by files 有权
检测并修复文件丢失的恶意软件

Detecting and remediating malware dropped by files
Abstract:
A security module detects and remediates malware from suspicious hosts. A file arrives at an endpoint from a host. The security module detects the arrival of the file and determines the host from which the file arrived. The security module also determines whether the host is suspicious. If the host is suspicious, the security module observes the operation of the file and identifies a set of files dropped by the received file. The security module monitors the files in the set using heuristics to detect whether any of the files engage in malicious behavior. If a file engages in malicious behavior, the security module responds to the malware detection by remediating the malware, which may include removing system changes caused by the set.
Public/Granted literature
Information query
Patent Agency Ranking
0/0