发明授权
US08214900B1 Method and apparatus for monitoring a computer to detect operating system process manipulation
有权
用于监测计算机以检测操作系统过程操纵的方法和装置
- 专利标题: Method and apparatus for monitoring a computer to detect operating system process manipulation
- 专利标题(中): 用于监测计算机以检测操作系统过程操纵的方法和装置
-
申请号: US12338587申请日: 2008-12-18
-
公开(公告)号: US08214900B1公开(公告)日: 2012-07-03
- 发明人: Sourabh Satish , William Sobel , Bruce McCorkendale
- 申请人: Sourabh Satish , William Sobel , Bruce McCorkendale
- 申请人地址: US CA Mountain View
- 专利权人: Symantec Corporation
- 当前专利权人: Symantec Corporation
- 当前专利权人地址: US CA Mountain View
- 代理机构: Wilmer Cutler Pickering Hale and Dorr LLP
- 主分类号: G06F12/14
- IPC分类号: G06F12/14
摘要:
A method and apparatus for monitoring a computer to detect operating system process manipulation by malicious software programs is disclosed. In one embodiment, a method for detecting operating system process manipulation through unexpected process behavior includes accessing process behavior indicia regarding memory addresses used by at least one user mode process to request computer resources and comparing the process behavior indicia with a user mode request to identify operating system process manipulation.
信息查询