首页> 外国专利> APPARATUS AND METHOD FOR DETECTION OF MALICIOUS PROGRAM USING PROGRAM BEHAVIOR

APPARATUS AND METHOD FOR DETECTION OF MALICIOUS PROGRAM USING PROGRAM BEHAVIOR

机译:利用程序行为检测恶意程序的装置和方法

摘要

The present invention is a method and apparatus for a computer program that runs on the computer system to diagnose whether or not the malware relates, more particularly, to a computer program and an apparatus and method for diagnosing whether a malicious program using the action of a computer program, to a method and apparatus for generating the device. ; This invention diagnosis based on behavior characteristics extracted from the target program to generate a first feature vector behavior according to behavior characteristic vector generation unit, already stored diagnostic data storing a plurality of second feature vector for a plurality of samples action program known whether the rogue part, and compared the action of the first feature vector and the vector of the plurality of second characteristic behavior, infection diagnosis unit diagnosing the target program is characterized in that it comprises a cord diagnosis for diagnosing whether an infection is provided . ; by the action of a computer program executed on a computer system according to the present invention, if a particular computer program code is normal, it can be determined whether the infection.
机译:本发明是一种用于在计算机系统上运行以诊断恶意软件是否与之相关的计算机程序的方法和设备,更具体地,涉及一种计算机程序以及用于利用恶意软件的行为来诊断恶意程序是否是恶意软件的设备和方法。计算机程序,用于生成设备的方法和装置。 ;本发明基于从目标程序中提取的行为特征进行诊断,以根据行为特征向量生成单元生成第一特征向量行为,已经存储的诊断数据存储了多个第二特征向量,用于多个样本动作程序,已知是否为流氓部分并且,通过比较第一特征向量和多个第二特征行为的向量的作用,诊断目标程序的感染诊断单元的特征在于,其包括用于诊断是否提供感染的线缆诊断。 ;通过根据本发明在计算机系统上执行的计算机程序的作用,如果特定的计算机程序代码正常,则可以确定是否感染。

著录项

  • 公开/公告号KR101329141B1

    专利类型

  • 公开/公告日2013-11-21

    原文格式PDF

  • 申请/专利权人

    申请/专利号KR20070099977

  • 申请日2007-10-04

  • 分类号G06F21/00;

  • 国家 KR

  • 入库时间 2022-08-21 15:44:21

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号