Invention Grant
- Patent Title: Detecting and remediating malware dropped by files
- Patent Title (中): 检测并修复文件丢失的恶意软件
-
Application No.: US12914949Application Date: 2010-10-28
-
Publication No.: US08832835B1Publication Date: 2014-09-09
- Inventor: Joseph H. Chen , Zhongning Chen
- Applicant: Joseph H. Chen , Zhongning Chen
- Applicant Address: US CA Mountain View
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Mountain View
- Agency: Fenwick & West LLP
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F12/14 ; G06F12/16 ; G08B23/00 ; G06F21/00 ; H04L29/06

Abstract:
A security module detects and remediates malware from suspicious hosts. A file arrives at an endpoint from a host. The security module detects the arrival of the file and determines the host from which the file arrived. The security module also determines whether the host is suspicious. If the host is suspicious, the security module observes the operation of the file and identifies a set of files dropped by the received file. The security module monitors the files in the set using heuristics to detect whether any of the files engage in malicious behavior. If a file engages in malicious behavior, the security module responds to the malware detection by remediating the malware, which may include removing system changes caused by the set.
Public/Granted literature
- US2658313A Grinding machine Public/Granted day:1953-11-10
Information query