首页> 外国专利> MALICIOUS CODE DETECTION METHOD USING VIRTUAL ENVIRONMENT, CAPABLE OF REDUCING WRONG DETECTION RATE BY REGISTERING PROCESS, NETWORK, FILE GENERATION, AND REGISTRY AS EXCEPTIONAL MATTERS

MALICIOUS CODE DETECTION METHOD USING VIRTUAL ENVIRONMENT, CAPABLE OF REDUCING WRONG DETECTION RATE BY REGISTERING PROCESS, NETWORK, FILE GENERATION, AND REGISTRY AS EXCEPTIONAL MATTERS

机译:使用虚拟环境的恶意代码检测方法,能够通过将过程,网络,文件生成和注册作为特殊事项来降低错误检测率

摘要

PURPOSE: A malicious code detection method using virtual environment is provided to increase the efficiency of malicious code detection by comprehensively analyzing newly created process, network connection, files, and registry information.;CONSTITUTION: An attached file is separated from a received mail. The attached file is transmitted to a distributor(S1). The transmitted attached file is transmitted to an attached file analyzer(S2). The characteristic of the transmitted attached file is analyzed. The analyzed attached file is transmitted to a virtual environment analyzer(S3). The existence of the malicious code is determined by executing the transmitted attached file in the virtual environment(S5). If the malicious code is detected in the attached file, a separate document file is notified to an e-mail recipient(S6).;COPYRIGHT KIPO 2010
机译:目的:通过全面分析新创建的进程,网络连接,文件和注册表信息,提供了一种使用虚拟环境的恶意代码检测方法,以提高恶意代码检测的效率。组成:附件和接收的邮件分开。附件被发送到分发者(S1)。所发送的附件被发送到附件分析器(S2)。分析了发送的附件的特征。被分析的附件被发送到虚拟环境分析器(S3)。通过在虚拟环境中执行发送的附件来确定恶意代码的存在(S5)。如果在附件中检测到恶意代码,则将单独的文档文件通知给电子邮件收件人(S6)。; COPYRIGHT KIPO 2010

著录项

  • 公开/公告号KR100927240B1

    专利类型

  • 公开/公告日2009-11-16

    原文格式PDF

  • 申请/专利权人 IGLOO SECURITY INC.;

    申请/专利号KR20090050662

  • 发明设计人 HAN EUN SEOB;

    申请日2009-06-08

  • 分类号G06F21;G06F21/22;G06F15/167;

  • 国家 KR

  • 入库时间 2022-08-21 18:33:47

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号