首页> 外国专利> SYSTEM AND METHOD FOR EVALUATING malicious code executed in the address space of a trusted process

SYSTEM AND METHOD FOR EVALUATING malicious code executed in the address space of a trusted process

机译:评估在受信任进程的地址空间中执行的恶意代码的系统和方法

摘要

1. Evaluation System of malicious code executing in the address space of a trusted process which comprises: a) the process monitoring means for monitoring processes run on the basis of unreliable features untrusted process, stored in the sign data and unreliable transmission process identifiers pickup means critical functions; b) base data attributes for storing information about the symptoms of unreliable processes and the provision of these features means the Mon itoringa processes a) means for intercepting calls critical features designed to intercept calls critical functions performed on behalf of at least one untrusted process, based on information stored in a database of critical functions, and transmitting the call information critical function analyzing means d) a database of critical functions for storing information on critical functions and information transmission means of said call interception critical functions; d) analyzing means, rednaznachennoe for identification by analysis of the stack executable code calls invoking critical function, and evaluation of harmfulness of said code on the basis of criteria on which information is stored in the criteria data; e) the base of these criteria, for storing information on the criteria for severity of executable code and transmission said information means analiza.2. The system of claim 1, wherein the analyzing means evaluates the severity code copies the addresses return function calls which
机译:1.在可信过程的地址空间中执行的恶意代码评估系统,包括:a)过程监视装置,用于监视基于不可靠特征,不可信过程,存储在符号数据中和不可靠传输过程标识符拾取装置的过程关键功能; b)用于存储有关不可靠进程的症状的信息的基本数据属性,这些功能的提供意味着监控程序a)拦截呼叫关键功能的手段,旨在拦截代表至少一个不受信任进程执行的呼叫关键功能,基于关于存储在关键功能数据库中的信息,并发送呼叫信息关键功能分析装置; d)用于存储关于关键功能的信息的关键功能数据库和所述呼叫拦截关键功能的信息传输装置; d)分析装置,用于通过分析调用堆栈的可执行代码调用的关键函数来进行标识的rednaznachennoe,以及基于将信息存储在标准数据中的标准来评估所述代码的危害性; e)这些标准的基础,用于存储有关可执行代码严重性标准的信息并传输,所述信息表示分析。 2.根据权利要求1所述的系统,其中,所述分析装置评估所述严重性代码,以复制所述地址返回函数调用,

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号