会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 23. 发明申请
    • NETWORK-BASED INFECTION DETECTION USING HOST SLOWDOWN
    • 基于网络的感染检测使用主站缓存
    • US20090126019A1
    • 2009-05-14
    • US12037212
    • 2008-02-26
    • Nasir MEMONHusrev Taha SencarKulesh Shanmugasundaram
    • Nasir MEMONHusrev Taha SencarKulesh Shanmugasundaram
    • G06F21/00
    • H04L63/1416G06F21/552
    • Host malware (or change) may be detected by (1) receiving baseline set of response time information for each of one or more transactions involving (A) the host and (B) at least one peer of the host, (2) determining or receiving a later set of response time information for each of the one or more transactions involving the host and the at least one peer of the host, and (3) determining whether or not host slowdown has occurred using the baseline set of response time information and the later set of response time information. The execution of a host malware (or change) protection policy may be controlled using at least the determination of whether or not host slowdown has occurred.
    • 主机恶意软件(或更改)可以通过以下方式来检测:(1)接收涉及(A)主机和(B)主机的至少一个对等体的一个或多个事务中的每一个的响应时间信息的基准集合,(2)确定或 接收涉及所述主机和所述主机的所述至少一个对等体的所述一个或多个事务中的每一个的稍后一组响应时间信息,以及(3)使用所述基准线响应时间信息确定是否发生了主机减速;以及 后一组响应时间信息。 主机恶意软件(或更改)保护策略的执行可以使用至少是否已经发生主机减速的确定来控制。