Invention Grant
US09330260B1 Detecting auto-start malware by checking its aggressive load point behaviors
有权
通过检查自动启动恶意软件的积极负载点行为来检测自动启动恶意软件
- Patent Title: Detecting auto-start malware by checking its aggressive load point behaviors
- Patent Title (中): 通过检查自动启动恶意软件的积极负载点行为来检测自动启动恶意软件
-
Application No.: US13951226Application Date: 2013-07-25
-
Publication No.: US09330260B1Publication Date: 2016-05-03
- Inventor: Fanglu Guo
- Applicant: Symantec Corporation
- Agency: Patent Law Works LLP
- Main IPC: H04L29/00
- IPC: H04L29/00 ; G06F21/56

Abstract:
Program behaviors concerning load points are monitored, and a specific program attempting to actively maintain a previously set value of a specific load point is detected. In response, the specific program is adjudicated to be malware, and one or more actions are performed to protect the computer. The monitored behavior can be write operations targeting load points. In this scenario, the behavior indicating that a program is malware can comprise performing a requisite number of write operations to a load point within a requisite time period. The monitored behavior can also be altering load point values, and monitoring the results. The altering of load points can comprise removing values specifying programs to run, and/or changing names of programs. Detecting that a specific altered load point value has been automatically reset within a requisite time period to run the specific program upon start-up indicates that the program is malware.
Information query