首页> 外国专利> Malicious script detection using context-dependent script emulation

Malicious script detection using context-dependent script emulation

机译:使用上下文相关脚本仿真进行恶意脚本检测

摘要

One embodiment relates to a computer-implemented process for detecting malicious scripts at a client computer using a malicious script detector. A web page interceptor intercepts an access of web page data at a universal resource locator address. A script preprocessor determines script fragments embedded in the web page data and extracts variable and function names from the script fragments. A context analyzer determines whether the script fragments reference known-good scripts. The context analyzer may check variable and function names in the script fragment against a database of known-good contexts. Those script fragments which were determined to reference known-good scripts may be categorized as non-malicious. An emulator may perform emulation on remaining script fragments which were not determined to reference known-good scripts and not perform emulation on the script fragments which were determined to reference known-good scripts. Other embodiments, aspects and features are also disclosed.
机译:一个实施例涉及一种用于利用恶意脚本检测器在客户端计算机上检测恶意脚本的计算机实现的过程。网页拦截器在通用资源定位器地址拦截网页数据的访问。脚本预处理器确定嵌入在网页数据中的脚本片段,并从脚本片段中提取变量和函数名称。上下文分析器确定脚本片段是否引用已知良好的脚本。上下文分析器可以根据已知良好上下文的数据库检查脚本片段中的变量和函数名称。被确定为引用已知良好脚本的那些脚本片段可以分类为非恶意的。仿真器可以对未确定参考已知良好脚本的其余脚本片段执行仿真,并且不对确定参考已知良好脚本的脚本片段执行仿真。还公开了其他实施例,方面和特征。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号