The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Dec. 12, 2017

Filed:

Dec. 29, 2014
Applicant:

Baidu Online Network Technology (Beijing) Co., Ltd, Beijing, CN;

Inventors:

Yinming Mei, Beijing, CN;

Yizhi Xie, Beijing, CN;

Huaming Yue, Beijing, CN;

Hanzhong Hu, Beijing, CN;

Tingli Bi, Beijing, CN;

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 21/55 (2013.01); G06F 21/56 (2013.01); H04L 29/06 (2006.01); G06N 5/04 (2006.01);
U.S. Cl.
CPC ...
G06F 21/55 (2013.01); G06F 21/56 (2013.01); G06N 5/048 (2013.01); H04L 63/145 (2013.01); H04L 63/1408 (2013.01); G06F 2221/034 (2013.01);
Abstract

A method, apparatus and system for detecting a malicious process behavior. A detection apparatus monitors a process to obtain behavior information about a target process behavior, and then sends the behavior information to a server, which determines whether the target process behavior is a malicious process behavior. The detection apparatus can receive first operation indication information returned by the server according to a detection result of the target process behavior, and perform an operation on the target process behavior according to the first operation indication information. The target process behavior is subjected to a comprehensive detection by the server according to the behavior information, rather than depending on a specified feature analysis of a single sample of the target process behavior by the detection apparatus, so that malicious process behavior can be detected in time, thereby improving the security performance of the system.


Find Patent Forward Citations

Loading…