CA3036007A1 - Procede d'identification et d'elimination de logiciels malveillants - Google Patents
Procede d'identification et d'elimination de logiciels malveillants Download PDFInfo
- Publication number
- CA3036007A1 CA3036007A1 CA3036007A CA3036007A CA3036007A1 CA 3036007 A1 CA3036007 A1 CA 3036007A1 CA 3036007 A CA3036007 A CA 3036007A CA 3036007 A CA3036007 A CA 3036007A CA 3036007 A1 CA3036007 A1 CA 3036007A1
- Authority
- CA
- Canada
- Prior art keywords
- specific file
- remote server
- file
- identifying
- blacklist
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Abandoned
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Virology (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Information Transfer Between Computers (AREA)
Abstract
L'invention concerne un procédé visant à identifier et à éliminer du code malveillant, lequel procédé utilise un dispositif informatique personnel capable de communiquer avec un serveur distant. Le serveur distant gère une liste noire et une liste blanche. La liste noire est une liste de programmes qui sont connus pour contenir du code malveillant. La liste blanche est une liste de programmes qui sont connus pour être exempts de code malveillant. Le procédé commence lorsqu'une demande d'exploration est reçue. La demande d'exploration est une consigne qui enjoint au dispositif informatique personnel de travailler avec le serveur distant pour effectuer une exploration d'une collection de fichiers de façon à identifier du code malveillant. Le procédé réalise ensuite un processus d'évaluation en enclos pour identifier des fichiers dont il s'avère qu'ils contiennent du code malveillant. Le processus d'évaluation en enclos est une procédure de test en isolement qui exécute des fichiers de programmes pour détecter du code malveillant. Enfin, le procédé exécute un processus d'atténuation de menace si du code malveillant a été trouvé.
Applications Claiming Priority (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US201662350963P | 2016-06-16 | 2016-06-16 | |
| US62/350,963 | 2016-06-16 | ||
| PCT/IB2017/053606 WO2017216774A1 (fr) | 2016-06-16 | 2017-06-16 | Procédé d'identification et d'élimination de logiciels malveillants |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| CA3036007A1 true CA3036007A1 (fr) | 2017-12-21 |
Family
ID=60664432
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CA3036007A Abandoned CA3036007A1 (fr) | 2016-06-16 | 2017-06-16 | Procede d'identification et d'elimination de logiciels malveillants |
Country Status (5)
| Country | Link |
|---|---|
| EP (1) | EP3475867A4 (fr) |
| CN (1) | CN109791586A (fr) |
| AU (1) | AU2017283818A1 (fr) |
| CA (1) | CA3036007A1 (fr) |
| WO (1) | WO2017216774A1 (fr) |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US12455965B2 (en) * | 2021-02-08 | 2025-10-28 | Hewlett-Packard Development Company, L.P. | Malware scans |
| CN115113892A (zh) * | 2021-03-19 | 2022-09-27 | 网联清算有限公司 | 压缩代码包黑名单更新和代码核查方法、装置及电子设备 |
| CN113934625B (zh) * | 2021-09-18 | 2024-09-13 | 深圳市富匙科技有限公司 | 软件检测方法、设备及存储介质 |
Family Cites Families (10)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7137145B2 (en) * | 2002-04-09 | 2006-11-14 | Cisco Technology, Inc. | System and method for detecting an infective element in a network environment |
| WO2006052714A2 (fr) * | 2004-11-09 | 2006-05-18 | Jeffory Atkinson | Appareil et procede pour proteger des systemes de communication |
| US7673341B2 (en) * | 2004-12-15 | 2010-03-02 | Microsoft Corporation | System and method of efficiently identifying and removing active malware from a computer |
| WO2008017950A2 (fr) * | 2006-08-10 | 2008-02-14 | Rudra Technologies Pte Ltd. | Système et procédé de protection d'un ordinateur contre les maliciels dans un fichier executable sur la base de critères d'élimination |
| US8881284B1 (en) * | 2008-06-16 | 2014-11-04 | Symantec Operating Corporation | Method and system for secure network access using a virtual machine |
| US8386506B2 (en) * | 2008-08-21 | 2013-02-26 | Yahoo! Inc. | System and method for context enhanced messaging |
| US9047441B2 (en) * | 2011-05-24 | 2015-06-02 | Palo Alto Networks, Inc. | Malware analysis system |
| WO2014012106A2 (fr) * | 2012-07-13 | 2014-01-16 | Sourcefire, Inc. | Procédé et appareil permettant de détecter rétroactivement un logiciel malveillant ou autrement indésirable ainsi qu'un logiciel propre par une renumérisation intelligente |
| US8739287B1 (en) * | 2013-10-10 | 2014-05-27 | Kaspersky Lab Zao | Determining a security status of potentially malicious files |
| CN105491053A (zh) * | 2015-12-21 | 2016-04-13 | 用友网络科技股份有限公司 | 一种Web恶意代码检测方法及系统 |
-
2017
- 2017-06-16 CA CA3036007A patent/CA3036007A1/fr not_active Abandoned
- 2017-06-16 CN CN201780050520.5A patent/CN109791586A/zh active Pending
- 2017-06-16 WO PCT/IB2017/053606 patent/WO2017216774A1/fr not_active Ceased
- 2017-06-16 AU AU2017283818A patent/AU2017283818A1/en not_active Abandoned
- 2017-06-16 EP EP17812871.6A patent/EP3475867A4/fr not_active Withdrawn
Also Published As
| Publication number | Publication date |
|---|---|
| EP3475867A4 (fr) | 2019-07-03 |
| CN109791586A (zh) | 2019-05-21 |
| WO2017216774A1 (fr) | 2017-12-21 |
| EP3475867A1 (fr) | 2019-05-01 |
| AU2017283818A1 (en) | 2019-03-28 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US20170286684A1 (en) | Method for Identifying and Removing Malicious Software | |
| JP6644001B2 (ja) | ウイルス処理方法、装置、システム、機器及びコンピュータ記憶媒体 | |
| AU2011317734B2 (en) | Computer system analysis method and apparatus | |
| US9306968B2 (en) | Systems and methods for risk rating and pro-actively detecting malicious online ads | |
| JP4936294B2 (ja) | マルウェアに対処する方法及び装置 | |
| JP6916818B2 (ja) | 脆弱なアプリケーションの検出 | |
| CN101924761B (zh) | 一种依据白名单进行恶意程序检测的方法 | |
| US7774459B2 (en) | Honey monkey network exploration | |
| US11227049B1 (en) | Systems and methods of detecting malicious PowerShell scripts | |
| US20190250937A1 (en) | Managing virtual machine security resources | |
| US20130067577A1 (en) | Malware scanning | |
| US8732831B2 (en) | Detection of rogue software applications | |
| US20060075494A1 (en) | Method and system for analyzing data for potential malware | |
| US9288226B2 (en) | Detection of rogue software applications | |
| CN105631312B (zh) | 恶意程序的处理方法及系统 | |
| CA3002605A1 (fr) | Systeme et procedes de detection d'un maliciel d'algorithme de generation de domaine (dga) | |
| US8321910B1 (en) | Determining the source of malware | |
| US20070006311A1 (en) | System and method for managing pestware | |
| CA3036007A1 (fr) | Procede d'identification et d'elimination de logiciels malveillants | |
| Kasama et al. | Malware detection method by catching their random behavior in multiple executions | |
| CN104809394A (zh) | 病毒查杀的方法、装置及终端 | |
| Geniola et al. | A large-scale analysis of download portals and freeware installers | |
| US11188644B2 (en) | Application behaviour control |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| FZDE | Discontinued |
Effective date: 20230914 |