首页> 外国专利> Remote malware scanning capable of static and dynamic file analysis

Remote malware scanning capable of static and dynamic file analysis

机译:能够进行静态和动态文件分析的远程恶意软件扫描

摘要

A method of remote malware scanning comprises comparing at a first node (e.g. a host) file items of an electronic file (e.g. an Android app) to be scanned for malware with the file items of previously scanned electronic files that include a predetermined number of same file items than the app to be scanned, and generating a recipe that includes information for identifying the previously scanned app and one or more file items included in the app to be scanned, and the result of the comparison. The recipe is used at the server to reconstruct the app and execute a dynamic malware analysis on a runtime behaviour of the reconstructed app. The server may then send the result of the analysis to the host. A malware property query may be performed for the app and its file items before the aforementioned method, and the method may be initiated if the query yields an inconclusive result. Upon receiving the recipe, the server may request any missing files, i.e. files that are not readily available at the server or not sent along with the recipe, from the host.
机译:远程恶意软件扫描的方法包括:在第一节点(例如主机)处,将要进行恶意软件扫描的电子文件(例如,Android应用)的文件项与包括预定数量的相同文件的先前扫描的电子文件的文件项进行比较。与要扫描的应用程序相比的文件项,并生成包含用于标识先前扫描的应用程序的信息以及要扫描的应用程序中包含的一个或多个文件项的信息的配方,以及比较结果。该配方在服务器上用于重建应用程序,并对重建的应用程序的运行时行为执行动态恶意软件分析。然后,服务器可以将分析结果发送到主机。可以在前述方法之前对应用及其文件项执行恶意软件属性查询,并且如果查询产生不确定的结果,则可以启动该方法。在接收到配方时,服务器可以从主机请求任何丢失的文件,即,在服务器上不容易获得的文件或者没有与配方一起发送的文件。

著录项

  • 公开/公告号GB2555859A

    专利类型

  • 公开/公告日2018-05-16

    原文格式PDF

  • 申请/专利权人 F-SECURE CORPORATION;

    申请/专利号GB20160019288

  • 发明设计人 PEKKA RASANEN;VILLE LINDFORS;

    申请日2016-11-15

  • 分类号G06F21/56;

  • 国家 GB

  • 入库时间 2022-08-21 12:32:09

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号