首页> 外国专利> MALWARE AUTO-ANALYSIS SYSTEM AND METHOD USING KERNEL CALL-BACK MECHANISM

MALWARE AUTO-ANALYSIS SYSTEM AND METHOD USING KERNEL CALL-BACK MECHANISM

机译:利用核回调机制的恶意软件自动分析系统和方法

摘要

The present invention relates to an automatic malware analysis method using a kernel callback mechanism, in your computer's loading time If the process is generated or a function to register the neck of the internal driver in the kernel function that calls a callback PsSetCreateProcessNotifyRoutine (Callback) function, the process is removed, returns the process according to the generated event and the end of the process (return) receiving process monitor drivers; A function that exists inside the driver load time to register a callback function to call a function inside CmRegisterCallback for registry access and monitoring, return the registry to receive event registry monitor driver; File Monitor driver to register itself in the Filter Manager kernel drivers to get mini filter driver returns a file-related input events in the windows system exists; Events and processes, registry events and output events kernel drivers and applications to conduct the event collector stored in the shared memory area defined by only a selected group of monitored data receiving process is the pre-set via shared memory that can be accessed at the same time; includes. ;
机译:本发明涉及一种使用内核回调机制的自动恶意软件分析方法,在您的计算机的加载时间内生成该过程或在内核函数中注册内部驱动程序的颈部的函数,该函数调用回调PsSetCreateProcessNotifyRoutine(Callback)函数,将流程删除,根据生成的事件返回流程并在流程结束(返回)时接收流程监视器驱动程序;驱动程序加载时间内存在的一个函数,用于注册回调函数,以调用CmRegisterCallback内部的函数以进行注册表访问和监视,返回注册表以接收事件注册表监视器驱动程序; File Monitor驱动程序在Filter Manager内核驱动程序中注册自己,以获取mini filter驱动程序返回的文件相关输入事件在Windows系统中存在;事件和进程,注册表事件和输出事件,内核驱动程序和用于执行事件收集器的应用程序,该事件收集器存储在仅由选定的一组受监视数据接收进程定义的共享内存区域中,是通过可在同一位置访问的共享内存预先设置的时间;包括在内。 ;

著录项

  • 公开/公告号KR101174751B1

    专利类型

  • 公开/公告日2012-08-17

    原文格式PDF

  • 申请/专利权人

    申请/专利号KR20100093308

  • 发明设计人 정현철;임채태;오주형;

    申请日2010-09-27

  • 分类号G06F11/28;G06F11/22;G06F11/14;

  • 国家 KR

  • 入库时间 2022-08-21 17:07:35

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号