发明申请
- 专利标题: WINDOWS REGISTRY MODIFICATION VERIFICATION
- 专利标题(中): WINDOWS注册修改验证
-
申请号: US13628607申请日: 2012-09-27
-
公开(公告)号: US20130024941A1公开(公告)日: 2013-01-24
- 发明人: Alessandro Faieta , Jameson Beach , Douglas Bell
- 申请人: Alessandro Faieta , Jameson Beach , Douglas Bell
- 主分类号: G06F21/00
- IPC分类号: G06F21/00
摘要:
A method and system is provided by which unauthorized changes to the registry may be detected and that provides the capability to verify whether registry, or other system configuration data, changes that occur on a computer system are undesirable or related to possible malware attack before the changes become effective or are saved on the system. A method for verifying changes to system configuration data in a computer system comprises generating an identifier representing an entry in the system configuration data, packaging the identifier, and sending the packaged identifier to a client for verification. The identifier may be generated by hashing the first portion of the entry and the second portion of the entry to generate the identifier, or by filtering the first portion of the entry and hashing the filtered first portion of the entry and the second portion of the entry to generate the identifier.
公开/授权文献
- US09183386B2 Windows registry modification verification 公开/授权日:2015-11-10
信息查询