- 专利标题: Systems and methods for categorizing processes as malicious
-
申请号: US15063533申请日: 2016-03-08
-
公开(公告)号: US09894085B1公开(公告)日: 2018-02-13
- 发明人: Eduard Dmitriyev
- 申请人: Symantec Corporation
- 申请人地址: US CA Mountain View
- 专利权人: Symantec Corporation
- 当前专利权人: Symantec Corporation
- 当前专利权人地址: US CA Mountain View
- 代理机构: FisherBroyles, LLP
- 主分类号: H04L29/06
- IPC分类号: H04L29/06
摘要:
The disclosed computer-implemented method for categorizing processes as malicious may include (1) storing, in a security application that tracks event data for the computing device, data about an event triggered by an uncategorized process, (2) storing, in the security application, new data about an additional event triggered by an additional process that has not previously been determined to be connected to the uncategorized process, (3) comparing the new data about the additional event with the data about the event to determine whether the additional data shares a common variable with the data, (4) identifying, based on determining that the additional data shares the common variable with the data, a malicious chain of events that comprises the event and the additional event, and (5) categorizing the uncategorized process as malicious in response to identifying the malicious chain of events. Various other methods, systems, and computer-readable media are also disclosed.
信息查询