Apparatus and method for detecting malicious process
Abstract
Provided are an apparatus and method for detecting a malicious process. The apparatus includes: a process monitoring unit for monitoring a process generated in a computing environment; a target process setting unit for previously setting a test target process among the processes confirmed by the process monitoring unit; a process generation time change monitoring unit for monitoring if the target process set by the target process setting unit requests to change a generation time; a generation time change preventing unit for preventing a change in the generation time of the target process when the target process requests to change the generation time; and a malicious process detecting unit for determining that a child process of the target process set by the target process setting unit is a malicious process if the child process is generated within a predetermined reference time.

Term
Projected expiry 31 July 2028.
- Priority
- Filed
- Published
- Today
- Projected expiry
1 sheet
Sheet 1
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| WO0157629A2 | Cites | World Intellectual Property Organization (WIPO) | X | Search report | 1-13 |
| CARSTEN WILLEMS ET AL: "Toward Automated Dynamic Malware Analysis Using CWSandbox", IEEE SECURITY AND PRIVACY, IEEE COMPUTER SOCIETY, NEW YORK, NY, US, vol. 5, no. 2, 1 March 2007 (2007-03-01), pages 32 - 39, XP011175985, ISSN: 1540-7993 | Non-patent | – | – | Search report | – |
8 members in 4 offices; this record represents the family
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 20070090906 | Republic of Korea | – | |
| 20070090906 | Republic of Korea | A |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| EP2034422A2 | European Patent Office (EPO) | A2 | |
| KR20090025788A | Republic of Korea | A | |
| US2009070876A1 | United States of America | A1 | |
| JP2009064414A | Japan | A | |
| KR100897849B1 | Republic of Korea | B1 | |
| EP2034422A3This record | European Patent Office (EPO) | A3 | |
| JP4806428B2 | Japan | B2 | |
| US8091133B2 | United States of America | B2 |
11 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Application withdrawnWithdrawn18W | 18W | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION HAS BEEN WITHDRAWNSTAA | STAA | |
| First examination report despatched17Q | 17Q | |
| Designation fees paidAKX | AKX | |
| Request for examination filed17P | 17P | |
| Designated contracting statesAK | AK | |
| Request for extension of the european patentAX | AX | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | |
| Designated contracting statesAK | AK | |
| Request for extension of the european patentAX | AX | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI |
Numbers
- Publication
- 2034422
- Application
- 81615692
Titles3
- German
- Vorrichtung und Verfahren zur Erkennung schädlicher Prozesse
- English
- Apparatus and method for detecting malicious process
- French
- Appareil et procédé de détection de procédé malveillant
Classification
- CPC, 2
- G06F21/56
- G06F11/30
- IPC, 2
- G06F21 00
- G06F21 56
Designated states38
- Contracting states, 34
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Croatia
- Hungary
- Ireland
- Iceland
- Italy
- Liechtenstein
- Lithuania
- Luxembourg
- Latvia
- Monaco
and 10 moreShow fewer
- Malta
- Netherlands (Kingdom of the)
- Norway
- Poland
- Portugal
- Romania
- Sweden
- Slovenia
- Slovakia
- Türkiye
- Extension states, 4
- Albania
- Bosnia and Herzegovina
- North Macedonia
- Serbia