发明申请
US20120255014A1 SYSTEM AND METHOD FOR BELOW-OPERATING SYSTEM REPAIR OF RELATED MALWARE-INFECTED THREADS AND RESOURCES 审中-公开
相关恶意软件的线程和资源的下列操作系统修复的系统和方法

  • 专利标题: SYSTEM AND METHOD FOR BELOW-OPERATING SYSTEM REPAIR OF RELATED MALWARE-INFECTED THREADS AND RESOURCES
  • 专利标题(中): 相关恶意软件的线程和资源的下列操作系统修复的系统和方法
  • 申请号: US13074947
    申请日: 2011-03-29
  • 公开(公告)号: US20120255014A1
    公开(公告)日: 2012-10-04
  • 发明人: Ahmed Said Sallam
  • 申请人: Ahmed Said Sallam
  • 申请人地址: US CA Santa Clara
  • 专利权人: MCAFEE, INC.
  • 当前专利权人: MCAFEE, INC.
  • 当前专利权人地址: US CA Santa Clara
  • 主分类号: G06F21/00
  • IPC分类号: G06F21/00
SYSTEM AND METHOD FOR BELOW-OPERATING SYSTEM REPAIR OF RELATED MALWARE-INFECTED THREADS AND RESOURCES
摘要:
A security agent may be configured to: (i) execute on an electronic device at a level below all of the operating systems of the electronic device accessing a memory or processor resources of the electronic device; (ii) trap attempted accesses to the memory or the processor resources associated with function calls for thread synchronization objects associated with creation, suspension, or termination of one thread by another thread; (iii) in response to trapping each attempted access, record information associated with the attempted access in a history, the information including one or more identities of threads associated with the attempted access; (iv) determine whether a particular thread is affected by malware; and (iv) in response to a determining that the particular thread is affected by malware, analyze information in the history associated with the particular memory location or processor resource to determine one or more threads related to the particular thread.
信息查询
0/0