首页> 外国专利> METHOD AND DEVICE FOR IDENTIFYING A DISK BOOT SECTOR VIRUS, AND STORAGE MEDIUM

METHOD AND DEVICE FOR IDENTIFYING A DISK BOOT SECTOR VIRUS, AND STORAGE MEDIUM

机译:识别磁盘启动盘病毒和存储介质的方法和设备

摘要

The present application discloses a method and a device for identifying a disk boot sector virus, and a storage medium. The method comprises steps of: obtaining a known behavior pattern that is prestored, and obtaining a master boot record (MBR) and disk data called when the MBR is executed; establishing a simulated execution environment according to the MBR and the disk data obtained, and simulating an execution process of the MBR; analyzing and recording a simulated behavior pattern of the MBR during the process of simulating the execution process of the MBR; and identifying a disk boot sector virus via a contrast analysis between the recorded simulated behavior pattern and the known behavior pattern. The solution of the present application has the beneficial effect that a new boot sector virus can be identified timely and accurately.
机译:本申请公开了一种用于识别磁盘启动扇区病毒的方法和设备以及一种存储介质。该方法包括以下步骤:获得预存储的已知行为模式;以及获得主引导记录(MBR)和在执行MBR时调用的磁盘数据;以及根据MBR和获取的磁盘数据,建立模拟执行环境,并模拟MBR的执行过程;在模拟MBR执行过程的过程中,分析并记录MBR的模拟行为模式;通过记录的模拟行为模式和已知行为模式之间的对比分析来识别磁盘引导扇区病毒。本申请的解决方案具有有益的效果,即可以及时,准确地识别新的引导扇区病毒。

著录项

  • 公开/公告号WO2014114134A1

    专利类型

  • 公开/公告日2014-07-31

    原文格式PDF

  • 申请/专利权人 TENCENT TECHNOLOGY (SHENZHEN) COMPANY LIMITED;

    申请/专利号WO2013CN88142

  • 发明设计人 TAN WEN;

    申请日2013-11-29

  • 分类号G06F9/48;

  • 国家 WO

  • 入库时间 2022-08-21 15:48:21

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号