会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 5. 发明申请
    • DETECTING AND RESPONDING TO MALWARE USING LINK FILES
    • 使用链接文件检测并响应恶意软件
    • WO2011047296A2
    • 2011-04-21
    • PCT/US2010052892
    • 2010-10-15
    • MCAFEE INCKUMAR LOKESHRAMCHETTY HARINATH VISHWANATHKULKARNI GIRISH R
    • KUMAR LOKESHRAMCHETTY HARINATH VISHWANATHKULKARNI GIRISH R
    • G06F21/06G06F11/30G06F21/22
    • G06F21/51G06F21/554G06F21/56H04L63/145
    • Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for monitoring the generation of link files by processes on a computer and performing protection processes based on whether the link files target malicious objects or are generated by malicious processes. In one aspect, a method includes monitoring for a generation of a first file that includes a target path that points to an object; in response to monitoring the generation of the first file: determining whether the target path is a uniform resource locator; in response to determining that the target path is a uniform resource locator, identifying a process that caused the first file to be generated; determining whether the process is a prohibited process; in response to determining that the process is a prohibited process, performing one or more protection processes on the process and the first file; in response to determining that the process is not a prohibited process, determining whether the uniform resource locator is a prohibited uniform resource locator; in response to determining that the uniform resource locator is a prohibited uniform resource locator, performing one or more protection processes on the process and the first file.
    • 包括在计算机存储介质上编码的计算机程序的方法,系统和装置,用于通过计算机上的进程来监视链接文件的生成,并且基于链接文件是针对恶意对象还是由恶意进程生成来执行保护处理。 在一个方面,一种方法包括:监视包括指向对象的目标路径的第一文件的生成; 响应于监视第一文件的生成:确定目标路径是否是统一资源定位符; 响应于确定所述目标路径是统一资源定位符,识别导致所述第一文件被生成的过程; 确定该过程是否是被禁止的过程; 响应于确定所述进程是禁止进程,对所述进程和所述第一文件执行一个或多个保护进程; 响应于确定所述过程不是被禁止的过程,确定所述统一资源定位符是否是被禁止的统一资源定位符; 响应于确定所述统一资源定位符是禁止的统一资源定位符,对所述进程和所述第一文件执行一个或多个保护处理。