×

Malicious code infection cause-and-effect analysis

  • US 9,910,981 B2
  • Filed: 09/09/2014
  • Issued: 03/06/2018
  • Est. Priority Date: 12/28/2005
  • Status: Active Grant
First Claim
Patent Images

1. A method performed by a computing device for analyzing a malware infection, the method comprising:

  • receiving post-infection snapshots from a plurality of machines suspected of being infected with malware, the post-infection snapshots identifying monitored activities of machines suspected of being infected with malware subsequent to the machines being suspected of being infected with malware;

    comparing by the computing device the monitored activities of a post-infection snapshot of a machine to the monitored activities of the post-infection snapshots of other machines to identify monitored activities that are common across multiple post-infection snapshots of different machines and that may be caused by the malware; and

    providing by the computing device an alert regarding the identified monitored activities that are common across multiple post-infection snapshots.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×