×

METHOD AND APPARATUS FOR DETECTING THE MALICIOUS BEHAVIOR OF COMPUTER PROGRAM

  • US 20100293615A1
  • Filed: 10/15/2008
  • Published: 11/18/2010
  • Est. Priority Date: 10/15/2007
  • Status: Active Grant
First Claim
Patent Images

1. A method for detecting malicious behavior of a computer program, comprising:

  • monitoring an action executed by the computer program;

    searching for a monitored process set associated with the monitored action within a library of monitored process sets, the monitored process set including information of at least one suspicious process correlated with each other in creating relationships; and

    if the monitored process set associated with the monitored action is found, judging whether the monitored action belongs to malicious behavior by correlation analysis based on information recorded in the monitored process set found.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×