会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 8. 发明申请
    • Computer Security Systems and Methods Using Asynchronous Introspection Exceptions
    • 使用异步反思异常的计算机安全系统和方法
    • US20170039371A1
    • 2017-02-09
    • US15209317
    • 2016-07-13
    • Bitdefender IPR Management Ltd.
    • Sandor LUKACSCristian B. SIRBAndrei V. LUTAS
    • G06F21/56G06F3/06
    • G06F21/564G06F3/0622G06F3/0653G06F3/0673G06F21/53G06F21/54G06F21/55
    • Described systems and methods enable an efficient analysis of security-relevant events, especially in hardware virtualization platforms. In some embodiments, a notification handler detects the occurrence of an event within a virtual machine, and communicates the respective event to security software. The security software then attempts to match the respective event to a collection of behavioral and exception signatures. An exception comprises a set of conditions which, when satisfied by an tuple, indicates that the respective entity is not malicious. In some embodiments, a part of exception matching is performed synchronously (i.e., while execution of the entity that triggered the respective event is suspended), while another part of exception matching is performed asynchronously (i.e., after the triggering entity is allowed to resume execution).
    • 描述的系统和方法能够有效地分析与安全相关的事件,特别是在硬件虚拟化平台中。 在一些实施例中,通知处理程序检测虚拟机内的事件的发生,并将相应事件传送到安全软件。 安全软件然后尝试将相应的事件与行为和异常签名的集合相匹配。 一个例外包括一组条件,当满足元组时,表示相应的实体不是恶意的。 在一些实施例中,异步匹配的一部分被同步执行(即,当触发相应事件的实体的执行被暂停时),而异步匹配的另一部分被异步地执行(即,在触发实体被允许恢复执行之后 )。
    • 10. 发明申请
    • Complex Scoring for Malware Detection
    • 恶意软件检测的复杂评分
    • US20150101049A1
    • 2015-04-09
    • US14046728
    • 2013-10-04
    • Bitdefender IPR Management Ltd.
    • Sandor LUKACSRaul V. TOSAPaul BOCAGheorghe HAJMASANAndrei V. LUTAS
    • G06F21/56H04L29/06
    • G06F21/566G06F9/45558G06F21/554G06F2009/45587G06F2221/033G06F2221/2145H04L63/14
    • Described systems and methods allow protecting a computer system from malware such as viruses, Trojans, and spyware. For each of a plurality of executable entities (such as processes and threads executing on the computer system), a scoring engine records a plurality of evaluation scores, each score determined according to a distinct evaluation criterion. Every time an entity satisfies an evaluation criterion (e.g, performs an action), the respective score of the entity is updated. Updating a score of an entity may trigger score updates of entities related to the respective entity, even when the related entities are terminated, i.e., no longer active. Related entities include, among others, a parent of the respective entity, and/or an entity injecting code into the respective entity. The scoring engine determines whether an entity is malicious according to the plurality of evaluation scores of the respective entity.
    • 描述的系统和方法允许保护计算机系统免受诸如病毒,特洛伊木马和间谍软件的恶意软件。 对于多个可执行实体(诸如在计算机系统上执行的进程和线程)中的每一个,评分引擎记录多个评估分数,每个分数根据不同的评估标准确定。 每当实体满足评估标准(例如执行动作)时,更新实体的相应得分。 更新实体的分数可以触发与相应实体相关的实体的得分更新,即使相关实体被终止,即不再有效。 相关实体包括各自实体的父母,和/或将代码注入相应实体。 评分引擎根据相应实体的多个评价分数确定实体是否是恶意的。