×

Antivirus protection system and method for computers

  • US 20080066179A1
  • Filed: 09/11/2006
  • Published: 03/13/2008
  • Est. Priority Date: 09/11/2006
  • Status: Active Grant
First Claim
Patent Images

1. An antivirus protection system for computers, comprising:

  • a Process Behavior-Evaluating Unit for identifying programs existing in a user'"'"'s computer and classifying the programs as normal programs or suspect programs;

    a Program-Monitoring Unit for monitoring and recording actions and/or behaviors of the programs;

    a Correlation-Analyzing Unit for creating correlative trees and analyzing correlations of actions and/or behaviors of programs, the correlative trees comprising a process tree and a file tree;

    a Virus-Identifying Knowledge Base, comprising a Program-Behavior Knowledge Base and a Database of Attack-Identifying Rules; and

    a Virus-Identifying Unit for receiving program actions and/or behaviors captured by the Program-Monitoring Unit, comparing the captured actions and/or behaviors to information stored in the Program-Behavior Knowledge Base or the Database of Attack-Identifying Rules, in combination with information stored in the Process Behavior-Evaluating Unit, and calling the Correlation-Analyzing Unit to determine whether the program is a virus in dependence on the comparison.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×