System and method for strategic anti-malware monitoring
US10171490B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Jun 12, 2015 |
| Grant date | Jan 1, 2019 |
| Priority date | — |
| Expiry date | Jul 3, 2035 |
Classification
- Technology area (CPC G)Physics
- CPC primaryG06F21/56
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
The system and method described herein may leverage active network scanning and passive network monitoring to provide strategic anti-malware monitoring in a network. In particular, the system and method described herein may remotely connect to managed hosts in a network to compute hashes or other signatures associated with processes running thereon and suspicious files hosted thereon, wherein the hashes may communicated to a cloud database that aggregates all known virus or malware signatures that various anti-virus vendors have cataloged to detect malware infections without requiring the hosts to have a local or resident anti-virus agent. Furthermore, running processes and file system activity may be monitored in the network to further detect malware infections. Additionally, the network scanning and network monitoring may be used to detect hosts that may potentially be participating in an active botnet or hosting botnet content and audit anti-virus strategies deployed in the network.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.