发明授权
- 专利标题: Kernel-level security agent
- 专利标题(中): 内核级安全代理
-
申请号: US13492672申请日: 2012-06-08
-
公开(公告)号: US09043903B2公开(公告)日: 2015-05-26
- 发明人: David F. Diehl , Dmitri Alperovitch , Ion-Alexandru Ionescu , George Robert Kurtz
- 申请人: David F. Diehl , Dmitri Alperovitch , Ion-Alexandru Ionescu , George Robert Kurtz
- 申请人地址: US CA Irvine
- 专利权人: CrowdStrike, Inc.
- 当前专利权人: CrowdStrike, Inc.
- 当前专利权人地址: US CA Irvine
- 代理机构: Lee & Hayes, PLLC
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; G06F21/56 ; G06F9/46 ; G06F21/55
摘要:
A kernel-level security agent is described herein. The kernel-level security agent is configured to observe events, filter the observed events using configurable filters, route the filtered events to one or more event consumers, and utilize the one or more event consumers to take action based at least on one of the filtered events. In some implementations, the kernel-level security agent detects a first action associated with malicious code, gathers data about the malicious code, and in response to detecting subsequent action(s) of the malicious code, performs a preventative action. The kernel-level security agent may also deceive an adversary associated with malicious code. Further, the kernel-level security agent may utilize a model representing chains of execution activities and may take action based on those chains of execution activities.
公开/授权文献
- US20130333040A1 Kernel-Level Security Agent 公开/授权日:2013-12-12
信息查询