首页> 外国专利> Normalizing and detecting inserted malicious code

Normalizing and detecting inserted malicious code

机译:规范化和检测插入的恶意代码

摘要

A method, system, and computer program product for detecting malicious code insertion in data are provided in the illustrative embodiments. At an application executing using a processor and a memory in a data processing system, a script that has been inserted in a mix of code and content is detected. A content-related portion is removed from the script to form a remaining script structure, the content-related portion referring to the content in the mix. From the remaining script structure, a code construct is selected and replaced with an alphanumeric string to form a normalized construct. Whether the normalized construct matches, within a tolerance, a second normalized construct in a corpus of normalized scripts is determined. Responsive to the normalized construct matching the second normalized construct within the tolerance, a conclusion is drawn that the script is malicious.
机译:在说明性实施例中提供了用于检测数据中恶意代码插入的方法,系统和计算机程序产品。在使用数据处理系统中的处理器和存储器执行的应用程序中,检测已插入到代码和内容的混合中的脚本。从脚本中删除与内容有关的部分,以形成剩余的脚本结构,其中与内容有关的部分是指混合中的内容。从剩余的脚本结构中,选择一个代码构造,并用字母数字字符串替换以形成规范化构造。确定归一化的构建体是否在公差范围内匹配归一化脚本的语料库中的第二个归一化的构建体。响应于在公差范围内与第二个标准化构造匹配的标准化构造,得出了脚本是恶意的结论。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号