发明授权
US08214900B1 Method and apparatus for monitoring a computer to detect operating system process manipulation 有权
用于监测计算机以检测操作系统过程操纵的方法和装置

Method and apparatus for monitoring a computer to detect operating system process manipulation
摘要:
A method and apparatus for monitoring a computer to detect operating system process manipulation by malicious software programs is disclosed. In one embodiment, a method for detecting operating system process manipulation through unexpected process behavior includes accessing process behavior indicia regarding memory addresses used by at least one user mode process to request computer resources and comparing the process behavior indicia with a user mode request to identify operating system process manipulation.
信息查询
0/0