KEYBOARD MONITORING TO PROTECT CONFIDENTIAL DATA
    1.
    发明申请
    KEYBOARD MONITORING TO PROTECT CONFIDENTIAL DATA 审中-公开
    键盘监控以保护机密数据

    公开(公告)号:WO2017091876A1

    公开(公告)日:2017-06-08

    申请号:PCT/BR2016/000138

    申请日:2016-12-02

    Abstract: In an example embodiment described herein, keyboard monitoring logic is operable to obtain data typed into a keyboard. The data typed into the keyboard is compared with predefined protected data stored in a local credential file, if data typed into the keyboard matches predefined protected data stored in the credential file, the keyboard monitoring logic determines whether the destination of the typed data ( e.g. , the application, website, or both the application and website are stored in a whitelist. If the destination is not stored in the whitelist, the keyboard monitoring logic determines that an attempt of unauthorized access to protected data is occurring.

    Abstract translation: 在这里描述的示例实施例中,键盘监视逻辑可操作来获得键入到键盘中的数据。 如果键入键盘的数据与存储在凭证文件中的预定义受保护数据匹配,键入键盘的数据与存储在本地凭证文件中的预定义受保护数据相比较,键盘监控逻辑确定键入数据的目的地(例如,应用程序,网站或应用程序和网站都存储在白名单中,如果目标未存储在白名单中,则键盘监控逻辑确定发生了未经授权访问受保护数据的企图

    SELF-PROTECTING FILE PROTECTION
    2.
    发明申请
    SELF-PROTECTING FILE PROTECTION 审中-公开
    自我保护文件保护

    公开(公告)号:WO2016094990A1

    公开(公告)日:2016-06-23

    申请号:PCT/BR2015/000201

    申请日:2015-12-15

    CPC classification number: G06F21/6209

    Abstract: In example embodiments described herein, a device driver is employed to protect certain files. The device driver registers itself with an operating system and requests system notifications when a process attempts to delete, write data, or change attributes of a file. The device driver intercepts messages to delete, write data, or change attributes of a file and determines whether the request is for a protected file. If the request is for a protected file, the request is denied.

    Abstract translation: 在本文描述的示例实施例中,采用设备驱动程序来保护某些文件。 设备驱动程序向操作系统注册自身,并在进程尝试删除,写入数据或更改文件属性时请求系统通知。 设备驱动程序拦截消息以删除,写入数据或更改文件的属性,并确定请求是否为受保护的文件。 如果请求是受保护的文件,请求被拒绝。

    ASSISTIVE TECHNOLOGY FOR ANTI-MALWARE SOFTWARE
    3.
    发明申请
    ASSISTIVE TECHNOLOGY FOR ANTI-MALWARE SOFTWARE 审中-公开
    用于防恶意软件的协调技术

    公开(公告)号:WO2016127233A1

    公开(公告)日:2016-08-18

    申请号:PCT/BR2016/000011

    申请日:2016-02-10

    CPC classification number: G06F21/56 G06F21/64

    Abstract: Anti-malware software has two components that work in coordination: a browser component and a local-server component. The browser component runs within a web browser or other suitable application, and the browser component receives and forwards at least one web- related data set to the local-server component via an assistive-technology module. In response to receiving the at least one web-related data set sent from the browser component, the local-server component executes an algorithm on the at least one web-related data set or portions of the at least one web-related data set. As an example, the algorithm may be an anti-malware algorithm directed to determining whether the at least one web-related data set is either an authentic data set or potential malware.

    Abstract translation: 反恶意软件有两个组件协调工作:浏览器组件和本地服务器组件。 浏览器组件在web浏览器或其他合适的应用程序中运行,并且浏览器组件通过辅助技术模块接收并转发至少一个与web相关的数据集到本地服务器组件。 响应于接收到从浏览器组件发送的至少一个web相关数据集,本地服务器组件对至少一个web相关数据集或至少一个web相关数据集的一部分执行算法。 作为示例,算法可以是针对确定至少一个web相关数据集是真实数据集还是潜在恶意软件的反恶意软件算法。

    PROTECTION DRIVER FOR DEFENSE AGAINST PROCESS OR THREAD TERMINATION
    4.
    发明申请
    PROTECTION DRIVER FOR DEFENSE AGAINST PROCESS OR THREAD TERMINATION 审中-公开
    防止过程或螺纹终止的防护驱动器

    公开(公告)号:WO2016094985A1

    公开(公告)日:2016-06-23

    申请号:PCT/BR2015/000184

    申请日:2015-12-15

    CPC classification number: G06F9/46 G06F9/52 G06F9/54 G06F21/53

    Abstract: Computer systems Methods (implemented through instructions carried by a medium) and apparatus for protecting a process or thread (102, 202) against forced terminations are disclosed. The protection is accomplished by monitoring of commands targeting the processes or threads (102, 202) under protection. In one example embodiment (100), Operating Systems' API (108) usage is monitored by a Operating System Device Driver (104) using kernel hooks. In another example embodiment (200), that monitoring occurs using kernel callbacks.

    Abstract translation: 计算机系统公开了用于保护过程或线程(102,202)以防止强制终止的方法(通过介质承载的指令来实现)和装置。 通过监视针对保护的进程或线程(102,202)的命令来实现保护。 在一个示例实施例(100)中,操作系统的API(108)使用由使用内核钩的操作系统设备驱动程序(104)监视。 在另一示例实施例(200)中,使用内核回调进行监视。

Patent Agency Ranking