Malware detection using risk analysis based on file system and network activity
    1.
    发明授权
    Malware detection using risk analysis based on file system and network activity 有权
    基于文件系统和网络活动的风险分析的恶意软件检测

    公开(公告)号:US08479276B1

    公开(公告)日:2013-07-02

    申请号:US12981072

    申请日:2010-12-29

    IPC分类号: G06F7/04

    CPC分类号: G06F21/577

    摘要: A virtual machine computing platform uses a security virtual machine (SVM) in operational communications with a risk engine which has access to a database including stored patterns corresponding to patterns of filtered operational data that are expected to be generated during operation of the monitored virtual machine when malware is executing. The stored patterns may have been generated during preceding design and training phases. The SVM is operated to (1) receive raw operational data from a virtual machine monitor, the raw operational data obtained from file system operations and network operations of the monitored virtual machine; (2) apply rule-based filtering to the raw operational data to generate filtered operational data; and (3) in conjunction with the risk engine, perform a mathematical (e.g., Bayesian) analysis based on the filtered operational data and the stored patterns in the database to calculate a likelihood that the malware is executing in the monitored virtual machine. A control action is taken if the likelihood is sufficiently high.

    摘要翻译: 虚拟机计算平台使用安全虚拟机(SVM)与风险引擎进行操作通信,所述风险引擎可以访问数据库,所述数据库包括对应于预期在所监视的虚拟机的操作期间生成的经过过滤的操作数据的模式的存储模式, 恶意软件正在执行。 存储的模式可能在以前的设计和训练阶段已经生成。 运行SVM以(1)从虚拟机监视器接收原始操作数据,从文件系统操作获得的原始操作数据和被监视虚拟机的网络操作; (2)对原始操作数据应用基于规则的过滤以生成经过滤的操作数据; 和(3)结合风险引擎,基于过滤的操作数据和数据库中存储的模式执行数学(例如,贝叶斯)分析,以计算恶意软件在被监视的虚拟机中执行的可能性。 如果可能性足够高,则采取控制措施。

    METHOD AND SYSTEM FOR ADDING A CALLER IN A BLOCKED LIST
    2.
    发明申请
    METHOD AND SYSTEM FOR ADDING A CALLER IN A BLOCKED LIST 有权
    用于在阻塞列表中添加呼叫者的方法和系统

    公开(公告)号:US20100246795A1

    公开(公告)日:2010-09-30

    申请号:US12739759

    申请日:2008-11-11

    IPC分类号: H04M3/42

    摘要: A method and system for adding a caller (102) in a blocked list is provided. The blocked list is stored at a communication server (104). The method includes receiving (604) a call from the caller (102) at a communication device (108). Further, the method includes receiving (606) a set of inputs at the communication device (108) in response to the call. The set of inputs includes a set of instructions to add the caller (102) in the blocked list. Furthermore, the method includes transmitting (608) a call termination request to the communication server (104). The call termination request includes the set of instructions to add the caller (102) in the blocked list. Transmission of the call termination request initiates addition of the caller (102) in the blocked list at the communication server (104).

    摘要翻译: 提供了一种用于在被阻止的列表中添加呼叫者(102)的方法和系统。 阻塞列表存储在通信服务器(104)。 该方法包括在通信设备(108)处接收(604)来自呼叫者(102)的呼叫(604)。 此外,该方法包括响应于该呼叫在通信设备(108)处接收(606)一组输入。 该组输入包括一组用于将呼叫者(102)添加到阻塞列表中的指令。 此外,该方法包括向通信服务器(104)发送(608)呼叫终止请求。 呼叫终止请求包括将呼叫者(102)添加到阻塞列表中的一组指令。 呼叫终止请求的发送在通信服务器(104)发起阻塞列表中的呼叫者(102)的添加。

    METHOD AND APPARATUS TO FACILITATE USING A FEDERATION-BASED BENEFIT TO FACILITATE COMMUNICATIONS MOBILITY
    5.
    发明申请
    METHOD AND APPARATUS TO FACILITATE USING A FEDERATION-BASED BENEFIT TO FACILITATE COMMUNICATIONS MOBILITY 有权
    利用基于联邦的优势促进通信移动的方法和装置

    公开(公告)号:US20110103265A1

    公开(公告)日:2011-05-05

    申请号:US12593351

    申请日:2008-03-31

    IPC分类号: H04L12/16 H04L12/66

    CPC分类号: H04L63/0815 H04L65/1069

    摘要: While facilitating (101) a call session for a participating entity having at least one federation-based benefit, one then uses (102) that at least one federation-based benefit to facilitate communications mobility for the participating entity during the call session. Such a call session can comprise, for example and at least in part, a wireless call session. The federation-based benefit itself can be one provided by a content provider, a services provider, or the like.

    摘要翻译: 虽然为具有至少一个基于联盟的益处的参与实体促进(101)呼叫会话,然后,使用(102)至少一个基于联盟的收益来促进参与实体在呼叫会话期间的通信移动性。 这样的呼叫会话可以例如并且至少部分地包括无线呼叫会话。 基于联盟的利益本身可以是由内容提供商,服务提供商等提供的。

    Method and apparatus to facilitate using a federation-based benefit to facilitate communications mobility
    6.
    发明授权
    Method and apparatus to facilitate using a federation-based benefit to facilitate communications mobility 有权
    促进使用基于联合的益处以促进通信移动性的方法和装置

    公开(公告)号:US09059986B2

    公开(公告)日:2015-06-16

    申请号:US12593351

    申请日:2008-03-31

    IPC分类号: H04L12/16 H04L29/06

    CPC分类号: H04L63/0815 H04L65/1069

    摘要: While facilitating (101) a call session for a participating entity having at least one federation-based benefit, one then uses (102) that at least one federation-based benefit to facilitate communications mobility for the participating entity during the call session. Such a call session can comprise, for example and at least in part, a wireless call session. The federation-based benefit itself can be one provided by a content provider, a services provider, or the like.

    摘要翻译: 虽然为具有至少一个基于联盟的益处的参与实体促进(101)呼叫会话,然后,使用(102)至少一个基于联盟的收益来促进参与实体在呼叫会话期间的通信移动性。 这样的呼叫会话可以例如并且至少部分地包括无线呼叫会话。 基于联盟的利益本身可以是由内容提供商,服务提供商等提供的。

    Method and system for adding a caller in a blocked list
    9.
    发明授权
    Method and system for adding a caller in a blocked list 有权
    在阻止列表中添加呼叫者的方法和系统

    公开(公告)号:US08374328B2

    公开(公告)日:2013-02-12

    申请号:US12739759

    申请日:2008-11-11

    IPC分类号: H04M3/42

    摘要: A method and system for adding a caller (102) in a blocked list is provided. The blocked list is stored at a communication server (104). The method includes receiving (604) a call from the caller (102) at a communication device (108). Further, the method includes receiving (606) a set of inputs at the communication device (108) in response to the call. The set of inputs includes a set of instructions to add the caller (102) in the blocked list. Furthermore, the method includes transmitting (608) a call termination request to the communication server (104). The call termination request includes the set of instructions to add the caller (102) in the blocked list. Transmission of the call termination request initiates addition of the caller (102) in the blocked list at the communication server (104).

    摘要翻译: 提供了一种用于在被阻止的列表中添加呼叫者(102)的方法和系统。 阻塞列表存储在通信服务器(104)。 该方法包括在通信设备(108)处接收(604)来自呼叫者(102)的呼叫(604)。 此外,该方法包括响应于该呼叫在通信设备(108)处接收(606)一组输入。 该组输入包括一组用于将呼叫者(102)添加到阻塞列表中的指令。 此外,该方法包括向通信服务器(104)发送(608)呼叫终止请求。 呼叫终止请求包括将呼叫者(102)添加到阻塞列表中的一组指令。 呼叫终止请求的发送在通信服务器(104)发起阻塞列表中的呼叫者(102)的添加。