首页> 外国专利> DETECTION OF HARMFUL SOFTWARE WITH CROSS-REVIEW

DETECTION OF HARMFUL SOFTWARE WITH CROSS-REVIEW

机译:交叉检查检测有害软件

摘要

In an example, a cross-view detection engine is disclosed for detecting malware behavior. Malware may attempt to avoid detection by remaining in volatile memory for as long as possible, and writing to disk only when necessary. To avoid detection, the malware may also provide a pseudo-driver at a file system level that performs legitimate-looking dummy operations. A firmware-level driver may simultaneously perform malicious operations. The cross-view detection engine detects this behavior by deconstructing call traces from the file system-level operations, and reconstructing call traces from firmware-level operations. If the traces do not match, the object may be flagged as suspicious.
机译:在示例中,公开了用于检测恶意软件行为的跨视图检测引擎。恶意软件可能会尝试通过尽可能长时间地保留在易失性内存中并仅在必要时写入磁盘来避免检测。为了避免检测,恶意软件还可能在文件系统级别提供伪驱动程序,以执行看上去合法的虚拟操作。固件级别的驱动程序可能同时执行恶意操作。跨视图检测引擎通过从文件系统级操作中解构调用跟踪,并从固件级操作中重构调用跟踪来检测此行为。如果迹线不匹配,则该对象可能被标记为可疑。

著录项

  • 公开/公告号RU2017105533A3

    专利类型

  • 公开/公告日2018-08-22

    原文格式PDF

  • 申请/专利权人

    申请/专利号RU20170105533

  • 发明设计人

    申请日0000-00-00

  • 分类号G06F21/56;G06F21/50;

  • 国家 RU

  • 入库时间 2022-08-21 12:36:14

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号