首页> 外国专利> SYSTEMS AND METHODS FOR SCANNING PACKED PROGRAMS IN RESPONSE TO DETECTING SUSPICIOUS BEHAVIORS

SYSTEMS AND METHODS FOR SCANNING PACKED PROGRAMS IN RESPONSE TO DETECTING SUSPICIOUS BEHAVIORS

机译:响应于检测可疑行为而扫描打包程序的系统和方法

摘要

A computer-implemented method for scanning packed programs in response to detecting suspicious behaviors may include (1) executing a packed program that may include (i) malicious code that has been obfuscated within the packed program and (ii) unpacking code that deobfuscates and executes the malicious code when the packed program is executed, (2) monitoring, while the packed program is executing, how the packed program behaves, (3) detecting, while monitoring how the packed program behaves, a suspicious behavior of the malicious code that indicates that the unpacking code has deobfuscated and executed the malicious code, and (4) performing a security operation on the packed program in response to detecting the suspicious behavior of the malicious code. Various other methods, systems, and computer-readable media are also disclosed.
机译:一种用于响应于检测到可疑行为而扫描打包程序的计算机实现的方法,可以包括:(1)执行打包程序,该打包程序可以包括(i)已在打包程序内被混淆的恶意代码,以及(ii)解包并执行模糊化的代码执行打包程序时的恶意代码;(2)在打包程序正在执行时监视打包程序的行为;(3)在监视打包程序如何运行的同时检测恶意代码的可疑行为,该行为表明确认解包代码已经模糊处理并执行了恶意代码,以及(4)响应于检测到恶意代码的可疑行为,对打包后的程序执行安全操作。还公开了各种其他方法,系统和计算机可读介质。

著录项

  • 公开/公告号EP3105701A1

    专利类型

  • 公开/公告日2016-12-21

    原文格式PDF

  • 申请/专利权人 SYMANTEC CORPORATION;

    申请/专利号EP20150708938

  • 发明设计人 PEREIRA SHANE;

    申请日2015-02-10

  • 分类号G06F21/56;

  • 国家 EP

  • 入库时间 2022-08-21 14:02:43

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号