Abstract: A method of detecting malicious activity, including the steps of: intercepting activity in a processing system 100; detecting attributes of an un-assessed process 460 associated with the activity; comparing the process attributes and activity to a database 430 of attributes and activity associated with known malicious and non-malicious processes; and using an inference filter 470 to compute the likely maliciousness of the un-assessed process.
Type:
Application
Filed:
October 23, 2007
Publication date:
June 12, 2008
Applicant:
PC TOOLS TECHNOLOGY PTY LTD.
Inventors:
Simon Clausen, Rolf Repasi, Kien Sen Huang