首页> 外国专利> System and method for malicious software detection in multiple protocols

System and method for malicious software detection in multiple protocols

机译:用于多种协议的恶意软件检测的系统和方法

摘要

A system and a method for detecting malicious content associated with an electronic message are described. An electronic message, such as an e-mail, a chat request, a torrent file or a text message is initially received. The electronic message can then be compared to known viruses using pattern or signature matching techniques. The electronic message is then transmitted to a virtual machine which executes the electronic message in an environment simulating the destination computing system of the electronic message. The virtual machine monitors execution of the electronic message to identify one or more malicious actions and classifies the electronic message accordingly. For example, message component execution is monitored for attempts to access system files, attempts to access user information, attempts to transmit system configuration data or attempts to transmit user information.
机译:描述了一种用于检测与电子消息相关联的恶意内容的系统和方法。最初接收到诸如电子邮件,聊天请求,种子文件或文本消息之类的电子消息。然后可以使用特征码或特征码匹配技术将电子消息与已知病毒进行比较。然后将电子消息传输到虚拟机,该虚拟机在模拟电子消息的目标计算系统的环境中执行电子消息。虚拟机监视电子消息的执行以识别一个或多个恶意行为,并相应地对电子消息进行分类。例如,将监视消息组件的执行情况,以尝试访问系统文件,尝试访问用户信息,尝试传输系统配置数据或尝试传输用户信息。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号