Patent · US Active

System and method for protecting computers from unauthorized remote administration

US9811661B1 · kind B1 · utility

21Cited by
1References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateDec 21, 2016
Grant dateNov 7, 2017
Priority date
Expiry dateDec 21, 2036

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2221/034
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

Disclosed are system and method for protecting computers from unauthorized remote administration. One exemplary method comprises: intercepting events occurred in a computer system; determining parameters of each intercepted event for identifying each intercepted event as being relating to a first data transfer by an application in a computer network or a second data transfer to an application from a peripheral data input device of the computer system; determining two intercepted events as being dependent on each other; determining a rule defining a dependency of the parameters of the two intercepted events; determining a degree of similarity of the rule and a previously created rule; if the degree of similarity exceeding a selected threshold value, identifying at least one application based at least on the rule and the previously created rule; and analyzing the at least one application for detecting a remote administration application.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.