发明授权
US08955138B1 Systems and methods for reevaluating apparently benign behavior on computing devices
有权
重新评估计算设备上显然良性行为的系统和方法
- 专利标题: Systems and methods for reevaluating apparently benign behavior on computing devices
- 专利标题(中): 重新评估计算设备上显然良性行为的系统和方法
-
申请号: US13939600申请日: 2013-07-11
-
公开(公告)号: US08955138B1公开(公告)日: 2015-02-10
- 发明人: Atif Mahadik , Shreyans Mehta
- 申请人: Symantec Corporation
- 申请人地址: US CA Mountain View
- 专利权人: Symantec Corporation
- 当前专利权人: Symantec Corporation
- 当前专利权人地址: US CA Mountain View
- 代理机构: ALG Intellectual Property, LLC
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; G06F21/55
摘要:
A computer-implemented method for reevaluating apparently benign behavior on computing devices may include (1) receiving a plurality of reports from a plurality of computing systems that indicate that an attack that targeted each of the systems reached a specific stage on each system, (2) identifying behavioral data that includes, for each computing system within the plurality, a plurality of activities that the computing system observed before the attack reached the specific stage on the computing system, wherein the plurality of activities are of a type of activity that is relevant to detecting a prior stage of the attack, (3) analyzing the behavioral data to correlate the attack with at least one activity observed before the attack reached the specific stage, and (4) determining that the activity is suspect based at least in part on correlating the attack with the activity. Various other methods, systems, and computer-readable media are also disclosed.
信息查询