首页> 外国专利> REAL-TIME WEB-SHELL DETECTION DEVICE USING KERNEL-BASED FILE EVENT MONITORING FUNCTION AND METHOD THEREOF

REAL-TIME WEB-SHELL DETECTION DEVICE USING KERNEL-BASED FILE EVENT MONITORING FUNCTION AND METHOD THEREOF

机译:利用基于核的文件事件监视功能的实时Web-shell检测装置及其方法

摘要

The present invention relates to a web-shell direction technology, and more specifically, to a device for detecting a web-shell on a real-time basis by using a kernel-based file event inspection function and a method thereof. The device includes: a web page inspection module which inspects the status of an inspection target file and a backup file in a web page to inspect whether the web page is forged; a kernel-based collection and analysis module which uses the file event inspection function in a kernel mode to collect the file event information generated with respect to files in the directory of the web page on a real-time basis and inspects whether the files in the directory are forged by referencing the collected file event information; a web-shell inspection module which inspects whether the forged file is a web-shell file by using the forgery inspection result generated by the kernel-based collection and analysis module and the forgery inspection result of the web page inspection module; and an inspection corresponding module which notifies the web-shell file inspection result generated by the web-shell file inspection module and collects the content corresponding thereto.;COPYRIGHT KIPO 2016
机译:通过基于内核的文件事件检查功能实时检测网络外壳的装置及其方法技术领域本发明涉及一种基于网络的外壳方向技术,尤其涉及一种基于内核的文件事件检查功能实时检测网络外壳的装置及其方法。该设备包括:网页检查模块,用于检查网页中检查目标文件和备份文件的状态,以检查网页是否被伪造;基于内核的收集和分析模块,其以内核模式使用文件事件检查功能,实时收集针对网页目录中的文件生成的文件事件信息,并检查是否存在通过引用收集的文件事件信息来伪造目录;网页外壳检查模块,通过基于核的收集分析模块生成的伪造检查结果和网页检查模块的伪造检查结果,检查所述伪造文件是否为网页外壳文件; COPYRIGHT KIPO 2016;检查对应模块,用于通知所述Web-Shell文件检查模块生成的Web-Shell文件检查结果并收集其内容。

著录项

  • 公开/公告号KR20160003584A

    专利类型

  • 公开/公告日2016-01-11

    原文格式PDF

  • 申请/专利权人 WINS CO. LTD.;

    申请/专利号KR20150176770

  • 发明设计人 HAN CHEOL KYUKR;

    申请日2015-12-11

  • 分类号G06F21/55;G06F21/57;G06F21/64;

  • 国家 KR

  • 入库时间 2022-08-21 14:15:21

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号