Invention Grant
- Patent Title: Systems and methods for tracking malicious behavior across multiple software entities
-
Application No.: US16148242Application Date: 2018-10-01
-
Publication No.: US10706151B2Publication Date: 2020-07-07
- Inventor: Gheorghe F. Hajmasan , Radu M. Portase
- Applicant: Bitdefender IPR Management Ltd.
- Applicant Address: CY Nicosia
- Assignee: Bitdefender IPR Management Ltd.
- Current Assignee: Bitdefender IPR Management Ltd.
- Current Assignee Address: CY Nicosia
- Agency: Law Office of Andrei D. Popovici, PC
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F21/55

Abstract:
Described systems and methods allow protecting a computer system from malicious software. In some embodiments, a security application organizes a set of monitored executable entities (e.g., processes) into a plurality of groups, wherein members of a group are related by filiation and/or code injection. The security application may further associate a malice-indicative entity score with each monitored entity, and a malice-indicative group score with each entity group. Group scores may be incremented when a member of the respective group performs certain actions. Thus, even though actions performed by individual members may not be malware-indicative per se, the respective group score may capture collective malicious behavior and trigger malware detection.
Public/Granted literature
- US20190034634A1 Systems and Methods for Tracking Malicious Behavior Across Multiple Software Entities Public/Granted day:2019-01-31
Information query