×

Detecting malicious computer program activity using external program calls with dynamic rule sets

  • US 8,627,458 B2
  • Filed: 01/13/2004
  • Issued: 01/07/2014
  • Est. Priority Date: 01/13/2004
  • Status: Active Grant
First Claim
Patent Images

1. A computer program product embodied on a non-transitory tangible computer readable medium and provided on a computer that includes a central processing unit (CPU) and an operating system, the computer program product, comprising:

  • logging code operable to log a stream of external program calls during an execution of a computer program;

    primary set identifying code operable to identify, within said stream of external program calls, a primary set of one or more external program calls matching one or more rules indicative of malicious computer program activity from among a set of rules;

    secondary set identifying code operable to identify, within said stream, at least one secondary set of one or more external program calls associated with said primary set of one or more external program calls, wherein one of said at least one secondary set of one or more external program calls (2) precedes or succeeds said primary set of one or more external program calls within said stream of external program calls and (2) originates from the same computer program, memory region, or thread of the primary set of external program calls;

    modifying code operable to modify said set of rules such that said at least one secondary set of one or more external program calls are more strongly associated with malicious computer program activity than said primary set of said one or more external program calls by increasing a score value associated with the secondary set of one or more external program for use in triggering an anti-malware response;

    wherein said set of rules is modified to include a new rule corresponding to said secondary set of one or more external program calls, said new rule thereafter being used in addition to other rules within said set of rules.

View all claims
  • 11 Assignments
Timeline View
Assignment View
    ×
    ×