首页> 外国专利> Detecting malicious code based on deviations in executable image import resolutions and load patterns

Detecting malicious code based on deviations in executable image import resolutions and load patterns

机译:根据可执行映像导入分辨率和加载模式中的偏差检测恶意代码

摘要

Trusted executable images are run in a controlled environment, such as a dynamic malware analysis platform. For each trusted executable image, a corresponding baseline import-load signature is generated. This can be done by applying a cryptographic hash function to the specific instructions which resolve imports and/or load libraries, and their operands. Sample programs are run in the controlled environment and tested for maliciousness. Any executable image run by a given sample program in the controlled environment is identified, and an import-load signature of the executable image when run by the sample program is generated. The import-load signature of the executable image when run by the sample program is compared to the corresponding stored baseline import-load signature for the same executable image. The sample program is adjudicated as being benign or malicious based on at least the results of the comparison.
机译:受信任的可执行映像在受控环境中运行,例如动态恶意软件分析平台。对于每个受信任的可执行映像,都会生成一个相应的基准导入负载签名。这可以通过将密码哈希函数应用于解析导入和/或加载库及其操作数的特定指令来完成。示例程序在受控环境中运行,并进行了恶意测试。识别在受控环境中由给定示例程序运行的任何可执行映像,并在由示例程序运行时生成可执行映像的导入-负载签名。将示例程序运行时的可执行映像的导入负载签名与同一可执行映像的相应存储的基线导入负载签名进行比较。至少基于比较结果,示例程序被判定为良性或恶意。

著录项

  • 公开/公告号US10061924B1

    专利类型

  • 公开/公告日2018-08-28

    原文格式PDF

  • 申请/专利权人 SYMANTEC CORPORATION;

    申请/专利号US201514986362

  • 发明设计人 PRASHANT GUPTA;

    申请日2015-12-31

  • 分类号G06F11/00;G06F21/56;

  • 国家 US

  • 入库时间 2022-08-21 13:03:11

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号