Invention Grant
- Patent Title: Detecting and responding to malware using link files
- Patent Title (中): 使用链接文件检测和响应恶意软件
-
Application No.: US12579679Application Date: 2009-10-15
-
Publication No.: US08863282B2Publication Date: 2014-10-14
- Inventor: Lokesh Kumar , Harinath Vishwanath Ramchetty , Girish R. Kulkarni
- Applicant: Lokesh Kumar , Harinath Vishwanath Ramchetty , Girish R. Kulkarni
- Applicant Address: US CA Santa Clara
- Assignee: McAfee Inc.
- Current Assignee: McAfee Inc.
- Current Assignee Address: US CA Santa Clara
- Agency: Patent Capital Group
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/55 ; H04L29/06 ; G06F21/51 ; G06F21/56

Abstract:
Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for monitoring the generation of link files by processes on a computer and performing protection processes based on whether the link files target malicious objects or are generated by malicious processes. In one aspect, a method includes monitoring for a generation of a first file that includes a target path that points to an object; in response to monitoring the generation of the first file: determining whether the target path is a uniform resource locator; in response to determining that the target path is a uniform resource locator, identifying a process that caused the first file to be generated; determining whether the process is a prohibited process; in response to determining that the process is a prohibited process, performing one or more protection processes on the process and the first file; in response to determining that the process is not a prohibited process, determining whether the uniform resource locator is a prohibited uniform resource locator; in response to determining that the uniform resource locator is a prohibited uniform resource locator, performing one or more protection processes on the process and the first file.
Public/Granted literature
- US20110093952A1 DETECTING AND RESPONDING TO MALWARE USING LINK FILES Public/Granted day:2011-04-21
Information query