首页> 外国专利> System for detecting and blocking metamorphic malware using the Intermediate driver

System for detecting and blocking metamorphic malware using the Intermediate driver

机译:使用中间驱动程序检测和阻止变态恶意软件的系统

摘要

The present invention relates to a system and a method for detecting and blocking variants of malware using an intermediate driver and, more specifically, to a system and a method for detecting and blocking variants of malware using an intermediate driver which complements the shortcomings of a conventional signature analysis by proposing a model which analyzes state changes in a system and a network by using a network driver interface specification (NDIS) intermediate driver and detects and blocks malware having an irregular pattern in a kernel mode. The present invention detects state behavior by using protocol type, IP address, MAC, use port, length, and time information extracted from packet information.
机译:本发明涉及一种使用中间驱动程序来检测和阻止恶意软件的变种的系统和方法,更具体地,涉及一种使用中间驱动程序来检测和阻止恶意软件的变种的系统和方法,该系统和方法弥补了传统技术的缺点。通过提出一种模型来进行签名分析,该模型使用网络驱动程序接口规范(NDIS)中间驱动程序分析系统和网络中的状态变化,并在内核模式下检测并阻止具有不规则模式的恶意软件。本发明通过使用从分组信息中提取的协议类型,IP地址,MAC,使用端口,长度和时间信息来检测状态行为。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号