首页> 外国专利> Malware detection and classification based on memory semantic analysis

Malware detection and classification based on memory semantic analysis

机译:基于内存语义分析的恶意软件检测与分类

摘要

Systems and methods for malware detection and classification based on semantic analysis of memory dumps of malware are provided. According to one embodiment, a malware detector running within a computer system causes a sample file to be executed within a target process that is monitored by a process monitor of the malware detector. One or more memory dumps associated with the sample file are captured by the process monitor. A determination regarding whether the sample file represents malware is made by the malware detector by analyzing characteristics of at least one memory dump of the one or more memory dumps with reference to characteristics of memory dumps of a plurality of known malware samples.
机译:提供了用于基于对恶意软件的存储器转储的语义分析的恶意软件检测和分类的系统和方法。根据一个实施例,在计算机系统内运行的恶意软件检测器使样本文件在由恶意软件检测器的过程监视器监视的目标过程内执行。与示例文件关联的一个或多个内存转储由进程监视器捕获。恶意软件检测器通过参考多个已知恶意软件样本的存储器转储的特征分析一个或多个存储器转储中的至少一个存储器转储的特征,来确定关于样本文件是否代表恶意软件。

著录项

  • 公开/公告号US10417420B2

    专利类型

  • 公开/公告日2019-09-17

    原文格式PDF

  • 申请/专利权人 FORTINET INC.;

    申请/专利号US201615335224

  • 发明设计人 JIE ZHANG;

    申请日2016-10-26

  • 分类号G06F21/56;

  • 国家 US

  • 入库时间 2022-08-21 12:16:55

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号