首页> 外国专利> MALICIOUS SHELL CODE DETECTION DEVICE USING A DEBUG EVENT GENERATED IN THE EXECUTION OF A CODE EXCLUDING AN EXECUTION ATTRIBUTE AND A METHOD THEREOF

MALICIOUS SHELL CODE DETECTION DEVICE USING A DEBUG EVENT GENERATED IN THE EXECUTION OF A CODE EXCLUDING AN EXECUTION ATTRIBUTE AND A METHOD THEREOF

机译:使用在执行代码(执行属性除外)时生成的调试事件的恶意外壳代码检测设备及其方法

摘要

PURPOSE: A malicious shell code detection device using a debug event and a method thereof are provided to determine whether or not a non-executable file is malicious based on address range information, thereby detecting a malicious non-executable file before executing a malicious code.;CONSTITUTION: An alarm setting unit(130) generates a debug event when a mother process executes a code excluding an execution attribute. The mother process is generated by a mother program executing a non-executable file. An information storage unit(140) stores address range information of a memory into which normal modules are loaded. The normal modules are used by the mother process. When the debug event is generated, a malicious determination unit(150) determines whether or not the non-executable file is malicious by using the address range information. When the debug event is generated, the alarm setting unit injects a data execution alarm thread into a detection object process.;COPYRIGHT KIPO 2013;[Reference numerals] (100) Malicious shell code detection device; (110) Interface unit; (120) Process execution unit; (130) Alarm setting unit; (140) Information storage unit; (150) Malicious determination unit; (160) Cause analysis unit; (170) Malicious code extraction unit
机译:目的:提供一种使用调试事件的恶意外壳代码检测设备及其方法,以基于地址范围信息确定不可执行文件是否为恶意文件,从而在执行恶意代码之前检测到该不可执行文件。 ;组成:警报设置单元(130)在母进程执行除执行属性以外的代码时产生调试事件。母进程是由执行不可执行文件的母程序生成的。信息存储单元(140)存储已加载普通模块的存储器的地址范围信息。正常模块由母进程使用。当产生调试事件时,恶意确定单元(150)通过使用地址范围信息来确定不可执行文件是否是恶意的。当产生调试事件时,警报设置单元将数据执行警报线程注入到检测对象进程中。; COPYRIGHT KIPO 2013; [参考数字](100)恶意外壳代码检测设备; (110)接口单元; (120)流程执行单元; (130)警报设定单元; (140)信息存储单元; (150)恶意判定单位; (160)原因分析单元; (170)恶意代码提取单元

著录项

  • 公开/公告号KR101244731B1

    专利类型

  • 公开/公告日2013-03-18

    原文格式PDF

  • 申请/专利权人 AHNLAB INC.;

    申请/专利号KR20120100255

  • 发明设计人 LIM CHA SUNG;LEE JU SEOK;

    申请日2012-09-11

  • 分类号G06F21/00;G06F11/30;G06F11/36;

  • 国家 KR

  • 入库时间 2022-08-21 16:25:29

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号