首页> 外国专利> METHOD FOR ANALYZING SPYWARE AND COMPUTER SYSTEM

METHOD FOR ANALYZING SPYWARE AND COMPUTER SYSTEM

机译:间谍软件和计算机系统的分析方法

摘要

A method for analyzing spyware and a computer system that relates to communication technology are provided. A trace of an executed spyware process is captured by the computer system. The spyware process includes a data packet returning operation that transmits a data packet to a control host as a result of executing the spyware process. The data packet returning operation has a subprogram which is extracted from the execution trace. The subprogram includes at least one call interface. Semantic information from each component of information of the at least one call interface is analyzed and output. In this manner a specific format of a data packet returned to the control host is determined, a communication protocol of the spyware is obtained, and a user may rewrite control commands of the spyware according to the obtained communication protocol, to control execution of the spyware.
机译:提供了一种用于分析间谍软件的方法和一种涉及通信技术的计算机系统。计算机系统捕获了执行的间谍软件过程的痕迹。间谍软件处理包括数据包返回操作,该操作将执行间谍软件处理的结果发送到控制主机。数据包返回操作具有从执行跟踪中提取的子程序。该子程序包括至少一个调用接口。分析并输出来自至少一个呼叫接口的信息的每个组成部分的语义信息。以这种方式,确定返回到控制主机的数据包的特定格式,获得间谍软件的通信协议,并且用户可以根据所获得的通信协议重写间谍软件的控制命令,以控制间谍软件的执行。 。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号