首页> 外国专利> System and method for detecting malware targeting the boot process of a computer using boot process emulation

System and method for detecting malware targeting the boot process of a computer using boot process emulation

机译:使用启动过程仿真来检测针对计算机启动过程的恶意软件的系统和方法

摘要

System and method for detecting malware on a target computer system having a bootable device. Boot process information stored on the bootable device that at least partially defines a boot process of the target computer system is obtained, along with physical parameter data defining a storage arrangement structure of the bootable device. The boot process of the target computer system is emulated based on the boot process information and on the physical parameter data. The emulation includes executing instructions of the boot process information and tracking data accessed from the bootable device. A data structure representing the data accessed from the bootable device is stored during the emulation of the boot process. The data structure can be analyzed for any presence of boot process malware.
机译:用于在具有可启动设备的目标计算机系统上检测恶意软件的系统和方法。获得存储在可启动设备上的,至少部分地定义目标计算机系统的启动过程的启动过程信息,以及定义可启动设备的存储布置结构的物理参数数据。基于启动过程信息和物理参数数据来模拟目标计算机系统的启动过程。该仿真包括执行引导过程信息的指令以及跟踪从可引导设备访问的数据。在引导过程的仿真过程中,存储了表示从可引导设备访问的数据的数据结构。可以分析数据结构中是否存在启动过程恶意软件。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号