首页> 外国专利> METHOD AND APPARATUS FOR DETERMINING BEHAVIOUR INFORMATION CORRESPONDING TO DANGEROUS FILE

METHOD AND APPARATUS FOR DETERMINING BEHAVIOUR INFORMATION CORRESPONDING TO DANGEROUS FILE

机译:确定与危险文件相对应的行为信息的方法和装置

摘要

A method for determining behaviour information corresponding to a dangerous file in a computer device. The method comprises: when a dangerous file is detected, running the dangerous file in a virtual environment of the computer device, wherein the virtual environment comprises at least one virtual API identical to at least one real API in a real environment of the computer device; and monitoring the behaviour of the dangerous file in the virtual environment to obtain behaviour information corresponding to the dangerous file. According to the method, the behaviour information about the dangerous file can be rapidly obtained in the virtual environment without needing to artificially analyse the destructive behaviour of the dangerous file, so as to rapidly and comprehensively repair a real system of the computer device.
机译:一种用于确定与计算机设备中的危险文件相对应的行为信息的方法。该方法包括:当检测到危险文件时,在计算机设备的虚拟环境中运行该危险文件,其中,虚拟环境包括与计算机设备的真实环境中的至少一个真实API相同的至少一个虚拟API;监控虚拟环境中危险文件的行为,以获得与该危险文件相对应的行为信息。根据该方法,可以在虚拟环境中快速获取危险文件的行为信息,而无需人为地分析危险文件的破坏性行为,从而快速,全面地修复计算机设备的真实系统。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号