首页> 外国专利> METHOD OF EXTRACTING WINDOWS EXECUTABLE FILE USING HARDWARE BASED ON SESSION MATCHING AND PATTERN MATCHING AND APPRATUS USING THE SAME

METHOD OF EXTRACTING WINDOWS EXECUTABLE FILE USING HARDWARE BASED ON SESSION MATCHING AND PATTERN MATCHING AND APPRATUS USING THE SAME

机译:基于会话匹配和模式匹配的硬件提取WINDOWS可执行文件的方法及应用

摘要

A method and apparatus for extracting a windows executable file that can search for a pattern related to windows executable files among a large quantity of network packets using a hardware-based session tracking and pattern matching technology and that can extract all packets included in the corresponding session are provided. The method of extracting a windows executable file includes: collecting incoming packets having a payload according to a session of a reference packet having an MZ pattern; performing a portable executable (PE) pattern matching for the collected incoming packets; and forming a PE file based on at least one incoming packet satisfying the PE pattern matching.
机译:一种提取Windows可执行文件的方法和设备,该方法和设备可以使用基于硬件的会话跟踪和模式匹配技术在大量网络数据包中搜索与Windows可执行文件有关的模式,并且可以提取相应会话中包括的所有数据包提供。提取Windows可执行文件的方法包括:根据具有MZ模式的参考数据包的会话收集具有有效负载的输入数据包;对收集到的输入数据包执行便携式可执行(PE)模式匹配;基于至少一个满足PE模式匹配的输入报文,形成PE文件。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号