- 专利标题: System and method for malware analysis using thread-level event monitoring
-
申请号: US14493201申请日: 2014-09-22
-
公开(公告)号: US10671726B1公开(公告)日: 2020-06-02
- 发明人: Sushant Paithane , Michael Vincent , Sai Vashisht
- 申请人: FireEye, Inc.
- 申请人地址: US CA Milpitas
- 专利权人: FireEye Inc.
- 当前专利权人: FireEye Inc.
- 当前专利权人地址: US CA Milpitas
- 代理机构: Rutan Tucker, LLP
- 主分类号: G06F21/00
- IPC分类号: G06F21/00 ; G06F21/56 ; H04L29/06
摘要:
According to one embodiment, a computerized method comprises processing one or more objects by a first thread of execution that are part of a multi-thread process, monitoring events that occur during the processing of the one or more objects by the first thread, and storing information associated with the monitored events within an event log. The stored information comprises at least an identifier of the first thread to maintain an association between the monitored events and the first thread. Subsequently, the stored information within the event log is accessed for rendering a graphical display of the monitored events detected during processing of the one or more objects by the first thread on a display screen.
信息查询