首页> 外国专利> PE file unpacking system and method for static analysis of malicious code

PE file unpacking system and method for static analysis of malicious code

机译:PE文件解压缩系统和用于恶意分析的方法

摘要

The present invention relates to an executable file unpacking system and method for static analysis of malicious code, wherein the method according to the present invention receives a detection target file, checks whether a binary file is present, and extracts a hash value if the detection target file is a binary file pre-analysis step, the step of searching the database for the malicious code hash value corresponding to the extracted hash value, and if the malicious code hash value corresponding to the extracted hash value is not found, the signature-based packer detection module is and detecting a packer using the entropy-based packer detection module, if the signature-based packer detection module does not detect a packer with respect to the file to be detected, and infers whether or not it is packed using the entropy-based packer detection module. According to the present invention, the probability of detecting a malicious code is increased, and there is an advantage in that it can be detected at a high speed.
机译:本发明涉及可恶意代码的静态分析的可执行文件解包系统和方法,其中根据本发明的方法接收检测目标文件,检查是否存在二进制文件,并且如果检测目标则提取哈希值文件是一个二进制文件预分析步骤,对对应于提取的散列值的恶意代码散列值搜索数据库的步骤,如果找不到与提取的散列值对应的恶意代码哈希值,则基于签名包装器检测模块和使用基于熵的封隔器检测模块检测封隔器,如果基于签名的封隔器检测模块不检测到要检测到的文件的封隔器,并且Infers是使用熵包装基于包装器检测模块。根据本发明,增加了检测恶意代码的概率增加,并且存在它可以以高速检测到的优点。

著录项

  • 公开/公告号KR102335475B1

    专利类型

  • 公开/公告日2021-12-08

    原文格式PDF

  • 申请/专利权人 (주)모니터랩;

    申请/专利号KR20210000707

  • 发明设计人 김영중;김두환;

    申请日2021-01-05

  • 分类号G06F21/56;

  • 国家 KR

  • 入库时间 2022-08-24 22:40:43

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号