首页> 外国专利> Cryptographic block identification apparatus, cryptographic block identification method, and non-transitory computer readable recording medium storing cryptographic block identification program

Cryptographic block identification apparatus, cryptographic block identification method, and non-transitory computer readable recording medium storing cryptographic block identification program

机译:密码块识别装置,密码块识别方法和存储密码块识别程序的非暂时性计算机可读记录介质

摘要

The present invention relates to a cryptographic block identification apparatus which, in order to analyze encryption logic used by malware to conceal communication, identifies a cryptographic block where encryption logic is stored within a program of the malware. The cryptographic block identification apparatus includes a block candidate extraction part and a cryptographic block identification part. The block candidate extraction part analyzes an execution trace in which an execution step of malware is recorded, calculates an evaluation value representing cipher likeliness of the execution step based on whether or not an operation type that characterizes cipher likeliness of the execution step is included in the execution step, and extracts an execution step where the evaluation value exceeds a threshold L, as a block candidate which is a candidate of a cryptographic block. The cryptographic block identification part identifies a region of the execution trace in which the block candidates are consecutive beyond a threshold M, as a cryptographic block.
机译:密码块识别设备技术领域本发明涉及一种密码块识别设备,该密码块识别设备为了分析恶意软件用来隐藏通信的加密逻辑,识别其中加密逻辑存储在恶意软件的程序中的密码块。密码块识别设备包括块候选提取部分和密码块识别部分。候选候选块提取部分分析其中记录了恶意软件的执行步骤的执行轨迹,基于是否包括表征执行步骤的密码相似性的操作类型来计算表示执行步骤的密码相似性的评估值。执行步骤,并提取评估值超过阈值L的执行步骤作为候选块,该候选块是密码块的候选者。密码块识别部分将其中块候选连续超过阈值M的执行轨迹的区域识别为密码块。

著录项

  • 公开/公告号US10050798B2

    专利类型

  • 公开/公告日2018-08-14

    原文格式PDF

  • 申请/专利权人 MITSUBISHI ELECTRIC CORPORATION;

    申请/专利号US201515544982

  • 发明设计人 HIROKI NISHIKAWA;TAKUMI YAMAMOTO;

    申请日2015-02-06

  • 分类号H04L9/36;H04L9/06;G06F21/56;

  • 国家 US

  • 入库时间 2022-08-21 13:05:11

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号