【24h】

Proposal of a Method Detecting Malicious Processes

机译:检测恶意过程的方法的提议

获取原文

摘要

Malwares' communication detection methods based on communication characteristics have been proposed. However as malwares are getting more sophisticated and legitimate softwares' communication is getting diverse, it becomes harder to correctly tell malwares' communication and legitimate softwares' communication apart. Therefore we propose a method to check whether a process generating suspicious communication is malicious or not. This method focuses on malwares which impersonate a legitimate process by injecting malicious codes into the process. This method extracts two process images. One is obtained from a process to be checked (target process) generating suspicious communication. The other is obtained by executing the same executable as the target process in a clean Virtual Machine. Then the two process images are compared to extract injected codes. Finally the codes are verified whether the codes are malicious or not.
机译:提出了基于通信特性的恶意通信检测方法。然而,由于恶意恶魔越来越复杂,合法的软件的沟通正在变得多样化,因此更难正确地告诉恶魔们的沟通和合法的软件的交流。因此,我们提出了一种方法来检查生成可疑沟通的过程是否是恶意的。这种方法侧重于恶意恶魔,通过将恶意代码注入过程来冒充合法过程。该方法提取两个过程图像。一个是从要检查的过程(目标过程)生成可疑通信的过程中获得。通过在清洁虚拟机中执行与目标过程相同的可执行文件来获得另一个。然后将两个处理图像进行比较以提取注入代码。最后,验证代码是否是恶意的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号