首页> 外国专利> DEVICE AND METHOD FOR DYNAMICALLY MEASURING TRUSTED STATE OF COMPUTER BASED ON CALL STACK TRACK

DEVICE AND METHOD FOR DYNAMICALLY MEASURING TRUSTED STATE OF COMPUTER BASED ON CALL STACK TRACK

机译:基于呼叫堆栈轨迹动态测量计算机的可信状态的设备和方法

摘要

A device and method for dynamically measuring a trusted state of a computer based on a call stack track, relating to the field of information security. The device comprises a process monitoring unit, a thread monitoring unit, a state collection and construction unit, a state measurement unit, a user state contact unit, a state measurement matching unit, and a call stack track storage unit. The process monitoring unit and the thread monitoring unit are connected to the state collection and construction unit; the state collection and construction unit is connected to the state measurement unit; the state measurement unit is connected to the user state contact unit; the user state contact unit is connected to the state measurement matching unit; the state measurement matching unit is connected to the call stack track storage unit. According to the device and method, by monitoring a process, a thread and a thread call stack, and comparing with pre-stored possible function call stack data of a code, possible abnormal behaviors in a code execution flow are found, and compared with a dynamic trusted measurement solution of only monitoring a system call type, the detection strength and depth are further improved.
机译:一种用于基于呼叫堆栈轨道动态测量计算机的可信状态的设备和方法,与信息安全领域有关。该设备包括过程监视单元,线程监视单元,状态收集和构造单元,状态测量单元,用户状态联系人单元,状态测量匹配单元和呼叫堆栈跟踪存储单元。过程监控单元和线程监控单元连接到状态采集和构造单元;状态收集和施工单元连接到状态测量单元;状态测量单元连接到用户状态触点单元;用户状态接触单元连接到状态测量匹配单元;状态测量匹配单元连接到呼叫堆栈轨道存储单元。根据设备和方法,通过监视过程,线程和线程呼叫堆栈,并与代码的预先存储的可能的功能调用堆栈数据进行比较,找到代码执行流中的可能的异常行为,并与a比较仅监控系统呼叫类型的动态可信测量解决方案进一步提高了检测强度和深度。

著录项

  • 公开/公告号WO2021208353A1

    专利类型

  • 公开/公告日2021-10-21

    原文格式PDF

  • 申请/专利权人 NANJING INSTITUTE OF CYBER TECHNOLOGY CO. LTD.;

    申请/专利号WO2020CN115905

  • 发明设计人 FANG HAO;WU HEYI;

    申请日2020-09-17

  • 分类号G06F21/55;

  • 国家 CN

  • 入库时间 2022-08-24 21:51:55

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号