
基本信息:
- 专利标题: 一种异常检测方法、装置及系统
- 专利标题(英):Exception detection method, apparatus and system
- 申请号:CN200810212005.5 申请日:2008-09-09
- 公开(公告)号:CN101360023A 公开(公告)日:2009-02-04
- 发明人: 崔巍 , 顾凌志 , 杨玉奇 , 杜欢 , 白皓文
- 申请人: 成都市华为赛门铁克科技有限公司
- 申请人地址: 四川省成都市高新区西部园区清水河片区
- 专利权人: 成都市华为赛门铁克科技有限公司
- 当前专利权人: 成都市华为赛门铁克科技有限公司
- 当前专利权人地址: 四川省成都市高新区西部园区清水河片区
- 代理机构: 北京集佳知识产权代理有限公司
- 代理人: 逯长明
- 主分类号: H04L12/26
- IPC分类号: H04L12/26 ; H04L29/06
The invention discloses an abnormality detection method, device and system. Wherein, the embodiment of the method can be as follows: monitoring the behaviors of a software accessing registry; when the behaviors of the software accessing registry belong to an abnormal behavior feature model and / or do not belong to a normal behavior feature model, determining the software as a malicious software; or when the behaviors of the software accessing registry do not belong to the abnormal behavior feature model and / or belong to the normal behavior feature model, determining the software as a normal software; the normal behavior feature model is obtained by normal accessing and modeling the registry; and the abnormal behavior feature model is obtained by abnormal accessing and modeling the registry. As monitoring the registry occupies less resources and the malicious software has the generality of abnormal accessing behaviors, new vicious procedures can be judged without updating the signature library. In conclusion, the embodiment can realize detecting unknown attacks on condition that the embodiment occupies less system resources to achieve the aim of defending malicious attacks.