首页> 外国专利> MALICIOUS PROCESS DETECTION METHOD AND APPARATUS, ELECTRONIC DEVICE, AND STORAGE MEDIUM

MALICIOUS PROCESS DETECTION METHOD AND APPARATUS, ELECTRONIC DEVICE, AND STORAGE MEDIUM

机译:恶意过程检测方法和设备,电子设备和存储介质

摘要

Embodiments of the present application relate to the technical field of network security, and disclosed are a malicious process detection method and apparatus, an electronic device, and a storage medium. The method comprises: obtaining a target process requesting a network connection; obtaining a system call operation of the target process; and if the system call operation matches a target system call operation, determining that the target process is a malicious process. In the embodiments of the present application, the target process is first determined according to whether a network connection to the outside exists, and then, whether the target process is a malicious process is determined according to the system call operation of the target process, so that malicious processes established by a command interpreter of a system may be detected, and malicious processes that are not established according to system rules may also be detected, thereby greatly reducing the leakage rate of malicious processes and realizing more effective detection.
机译:本申请的实施例涉及网络安全技术领域,并且公开了一种恶意处理检测方法和装置,电子设备和存储介质。该方法包括:获取请求网络连接的目标过程;获取目标过程的系统调用操作;如果系统调用操作与目标系统调用操作匹配,则确定目标过程是恶意进程。在本申请的实施例中,首先根据是否存在与外部的网络连接是否存在,然后,根据目标过程的系统调用操作确定目标过程是否是恶意处理的,因此可以检测由系统的命令解释器建立的恶意处理,并且还可以检测根据系统规则确定的恶意处理,从而大大降低了恶意过程的泄漏率并实现了更有效的检测。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号