×

APPARATUS AND METHOD FOR DETECTING MALICIOUS PROCESS

  • US 20090070876A1
  • Filed: 04/16/2008
  • Published: 03/12/2009
  • Est. Priority Date: 09/07/2007
  • Status: Active Grant
First Claim
Patent Images

1. An apparatus for detecting a malicious process, comprising:

  • a process monitoring unit for monitoring a process generated in a computing environment;

    a target process setting unit for previously setting a test target process among the processes confirmed by the process monitoring unit;

    a file generation time change monitoring unit for monitoring if the target process set by the target process setting unit requests to change a file generation time;

    a file generation time change preventing unit for preventing a change in the file generation time of the target process when the target process requests to change the file generation time; and

    a malicious process detecting unit for determining that a child process of the target process set by the target process setting unit is a malicious process if the child process generates a file within a predetermined reference time.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×