WO2010117155A2 - Détecteur de code malveillant à système sur puce pour dispositif mobile - Google Patents
Détecteur de code malveillant à système sur puce pour dispositif mobile Download PDFInfo
- Publication number
- WO2010117155A2 WO2010117155A2 PCT/KR2010/001853 KR2010001853W WO2010117155A2 WO 2010117155 A2 WO2010117155 A2 WO 2010117155A2 KR 2010001853 W KR2010001853 W KR 2010001853W WO 2010117155 A2 WO2010117155 A2 WO 2010117155A2
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- chip
- memory
- malware
- unit
- firewall
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/606—Protecting data by securing the transmission between two devices or processes
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/562—Static detection
- G06F21/564—Static detection by virus signature recognition
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/71—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04B—TRANSMISSION
- H04B1/00—Details of transmission systems, not covered by a single one of groups H04B3/00 - H04B13/00; Details of transmission systems not characterised by the medium used for transmission
- H04B1/38—Transceivers, i.e. devices in which transmitter and receiver form a structural unit and in which at least one part is used for functions of transmitting and receiving
- H04B1/40—Circuits
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/12—Detection or prevention of fraud
- H04W12/121—Wireless intrusion detection systems [WIDS]; Wireless intrusion prevention systems [WIPS]
- H04W12/122—Counter-measures against attacks; Protection against rogue devices
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/12—Detection or prevention of fraud
- H04W12/126—Anti-theft arrangements, e.g. protection against subscriber identity module [SIM] cloning
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/12—Detection or prevention of fraud
- H04W12/128—Anti-malware arrangements, e.g. protection against SMS fraud or mobile malware
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2121—Chip on media, e.g. a disk or tape with a chip embedded in its case
Definitions
- the present invention relates to a technology for detecting malicious code applied to a mobile terminal, and in particular, a malicious code introduced into a mobile terminal by constructing a firewall and an anti-malware engine based on memory on a system-on-chip in consideration of resource and performance improvement of the mobile terminal.
- the present invention relates to a system-on-chip based malware detection apparatus for detecting a mobile terminal.
- PDAs personal digital assistants
- WiBro terminals these portable terminals are becoming a necessity for modern life.
- Many people use mobile devices to talk about each other, exchange information, and exchange business-critical information through voice and data communication.
- Examples of the mobile malicious code include a thymophonica worm, an I-mode malicious code, a short message service (SMS), a virus operating in a palm OS, and a virus (Phage, Vapor, Liberty).
- SMS short message service
- a virus operating in a palm OS a virus operating in a palm OS
- a virus a virus operating in a palm OS
- the anti-malware (Anti-Malware) solutions applied to conventional mobile terminals are based on software, and the basic operation thereof is as follows.
- the software-based antivirus program basically includes an anti-malware engine and a signature matching unit, and has a structure in which a virus signature database is periodically updated.
- a firewall applied to a conventional mobile terminal blocks all network access input from the outside or a network connection with a specific external external program according to policy setting.
- anti-malware solutions applied to conventional mobile terminals are built on software and used as mobile devices.
- mobile devices are relatively limited in resources such as central processing unit and battery, it is inconvenient for a user to perform other tasks besides malware detection due to performance degradation when using the existing model. Will suffer.
- an object of the present invention is to provide a memory-based memory system on a stem-on-chip in order to fundamentally solve the performance degradation of a software-based antivirus solution and to overcome the limitations of a software-based cooperative malware signature (malware signature) database. It is to provide a device that detects malicious code flowing into a mobile terminal by building a firewall and an anti-malware engine and changing the virus signature database to be locally reflected.
- malware signature malware signature
- Another object of the present invention is to establish a firewall and an anti-malware engine based on memory on a system-on-chip to detect malicious code, and to detect malware by referring to a pattern of malicious code registered in a malware signature database on the system-on-chip memory.
- a central processing unit that collectively controls each part in the system on chip to detect malicious codes based on the system on chip;
- Classify packets that are input from the outside through the network interface unit and perform filtering operations such as dropping and dropping the classified packets according to preset contents, and outputting the result to the application memory or the anti-malware engine.
- Filing operations such as dropping and dropping the classified packets according to preset contents, and outputting the result to the application memory or the anti-malware engine.
- a memory-based anti-malware engine for a system-on-chip anti-malware engine that detects malicious codes by performing a pattern matching operation between a code pattern in a file input from the firewall and a pattern of malicious code registered in a malware signature database on a system-on-chip memory;
- a memory-based control module for a system-on-chip for controlling the operation of the firewall and the anti-malware engine in association with the central processing unit;
- a system on chip configured as a malware signature database in which the pattern of the malicious code is stored.
- the mobile device application unit interacting with the system-on-chip is built in the application memory to update the vaccine version, and is connected to the mobile device application unit adopting the corresponding connection method according to the network used on the server side. .
- the present invention is configured on the system-on-chip based on the memory in the system-on-chip to detect malicious code flowing into the mobile terminal, thereby improving virus scanning and matching performance. Accordingly, there is an effect that can perform an antivirus service at the same time while performing other tasks on the mobile device.
- all packets can be monitored through a memory-based firewall in the system-on-chip, which helps to keep the mobile device more secure from mobile viruses.
- the anti-malware engine can quickly perform pattern matching and automatically update from the network even when the malware signature database is updated. It becomes possible.
- FIG. 1 is a block diagram of a system-on-chip based malware detection apparatus in a mobile terminal according to the present invention.
- FIG. 2 is a detailed block diagram of an application unit for a mobile device in FIG. 1.
- FIG. 2 is a detailed block diagram of an application unit for a mobile device in FIG. 1.
- firewall 131A packet identification unit
- packet filtering unit 132 anti-malware engine
- Control Module 133B Malware Signature Database
- peripheral device 200 application memory
- FIG. 1 is a block diagram showing an embodiment of a system-on-chip-based malware detection apparatus in a portable terminal according to the present invention.
- a mobile device application unit 210 on the application memory 200 connected to and connected to the system-on-chip 100 through the memory interface unit 150.
- the system-on-chip 100 is mounted on the main PCB of the portable terminal and operates in conjunction with the mobile device application unit 210 built on the application memory 200.
- the system-on-chip 100 is operated in an autonomous monitoring mode that is preprogrammed with a normal working state rule of an input / output data flow, and a mode for disabling input and output channels when a current state exceeds a normal state rule. .
- the central processing unit 110 includes each component built on the system on chip 100, that is, the network interface unit 120, the system on chip memory 130, the input / output interface unit 140, the memory interface unit 150, and the like. It serves to control the driving of the peripheral device 160 collectively.
- the CPU 110 drives the firewall 131, the anti-malware engine 132, the control module 133A, and the malware signature database 133B based on the system-on-chip memory 130 as described below. In the detection of malicious code, it takes the role of controlling to be performed at an appropriate cycle or time point in consideration of battery power consumption.
- the network interface unit 120 delivers packets newly received from the outside to be stored in the application memory 200 to the system on chip memory 130 under the control of the CPU 110.
- the system-on-chip memory 130 is an area in which components (code) for detecting malicious codes that can be repaired later are constructed, and a firewall configured of a packet identification unit 131A and a packet filtering unit 131B. 131, an anti-malware engine 132, a control module 133A, and a malware signature database 133B.
- the packet identification unit 131A classifies the input packets and outputs them to the packet filtering unit 131B.
- the packet filtering unit 131B performs filtering, such as 'allow' and 'drop' on the input packet according to the setting contents of the application memory 200.
- the packets filtered by the packet filtering unit 131B are transferred to the application memory 200 through the internal bus and the memory interface unit 150 under the control of the CPU 110 and the control module 133A. It may be stored or transmitted to the anti-malware engine 132 through its internal bus.
- the application memory 200 includes an operating system (OS) and various programs used in a mobile device.
- OS operating system
- the anti-malware engine 132 performs malware detection on the packet filtered file output from the packet filtering unit 131B and a file newly input from the input / output interface unit 20.
- the malware signature database 133B is built on the system-on-chip memory 130.
- the anti-malware engine 132 uses the pattern and the path of the malware registered in the malware signature database 133B to detect malware. Pattern matching between code patterns in the input file is performed.
- the control module 133A controls the driving of the firewall 131 and the anti-malware engine 132 in association with the central processing unit 110 so that they operate as described above.
- the system-on-chip 100 operating as described above is updated when a firewall code or an anti-malware engine code is changed or modified through a network.
- FIG. 2 illustrates a structure of the mobile device application unit 210 that is built on the application memory 200 and operates in conjunction with the system-on-chip 100. As shown in FIG. It consists of a database information unit 212.
- the application module 211 includes a version sync module 211A, an update module 211B, a center connection module 211C, and a tag generation module. 211D, the database information unit 212 is composed of a center URL information unit 212A and a device information unit 212B.
- the version synchronization module 211A compares the vaccine version of the server and the vaccine version of the mobile terminal at predetermined intervals, and if they are different, operates the update module 211B so that the vaccine version of the mobile terminal is updated to the latest version of the server. In addition, the version synchronization module 211A operates the update module 211B to update the vaccine version of the mobile terminal even in a situation where the malware signature database on the server side needs to be updated.
- the security policy is effective only when the vaccine version is updated frequently based on the vulnerabilities that occur constantly.
- the version synchronization module 211A operates the update module 211B even when the signature database on the server side needs to be updated so that the vaccine version of the mobile terminal is updated to the latest version.
- the center connection module 211C prioritizes the connection method and adopts the connection method according to the network used on the server side. For example, if WiFi is available, select a mobile carrier to connect via WiFi instead of accessing the center URL.
- the center URL information unit 212A is used to connect the mobile terminal with the network of the server side through the network interface unit 120 in the adopted connection method (eg, wireless LAN (eg, WiFi), mobile communication company). .
- the tag generation module 211D generates a tag for each operating system (OS) on the malware signature database 133B, and the generated tag is stored in the malware signature database 133B.
- OS operating system
- the tag generation module 211D may tag which local information and which version information the corresponding database is when the malware signature database 133B is updated.
- the version information and local information are stored and managed in the tag generation module 211D.
- the device information unit 212B serves to maintain information required by the device.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- Software Systems (AREA)
- General Physics & Mathematics (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Virology (AREA)
- Bioethics (AREA)
- Mathematical Physics (AREA)
- Computer And Data Communications (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
L'invention concerne une technique de construction de pare-feu et de moteur anti-logiciel malveillant reposant sur une mémoire pour système sur puce, dans le but de détecter des codes malicieux d'effraction sur dispositif mobile. On décrit à cet effet un système sur puce qui comprend: une unité centrale de traitement contrôlant chaque unité du système sur puce pour la détection de code malveillant de système sur puce; le pare-feu qui repose sur la mémoire pour système sur puce, classifiant les paquets reçus d'une source externe via une unité d'interface de réseau, effectuant un filtrage, par étapes d'autorisation et de rejet, sur les paquets classifiés selon les paramètres de réglage de pare-feu, puis transmettant le résultat du filtrage à une mémoire pour application, ou au moteur anti-logiciel malveillant; le moteur anti-logiciel malveillant qui repose sur la mémoire pour système sur puce, et qui effectue des correspondances de formes entre la forme de code du fichier reçu du pare-feu et la forme de code malveillant enregistrée dans une base de données de signatures de logiciel malveillant sur la mémoire pour système sur puce, dans le but de détecter des codes malveillants; et un module de contrôle reposant sur la mémoire pour système sur puce, qui contrôle le fonctionnement du pare-feu et du moteur anti-logiciel malveillant en coopération avec l'unité centrale de traitement.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR1020090030671A KR101058301B1 (ko) | 2009-04-09 | 2009-04-09 | 휴대단말기에서의 시스템온칩 기반의 악성코드 검출 장치 |
| KR10-2009-0030671 | 2009-04-09 |
Publications (3)
| Publication Number | Publication Date |
|---|---|
| WO2010117155A2 true WO2010117155A2 (fr) | 2010-10-14 |
| WO2010117155A3 WO2010117155A3 (fr) | 2011-01-20 |
| WO2010117155A9 WO2010117155A9 (fr) | 2011-03-10 |
Family
ID=42936679
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/KR2010/001853 Ceased WO2010117155A2 (fr) | 2009-04-09 | 2010-03-26 | Détecteur de code malveillant à système sur puce pour dispositif mobile |
Country Status (2)
| Country | Link |
|---|---|
| KR (1) | KR101058301B1 (fr) |
| WO (1) | WO2010117155A2 (fr) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103679023A (zh) * | 2013-10-10 | 2014-03-26 | 南京邮电大学 | 一种联合计算架构下的海量病毒报告分析方法 |
| WO2019081270A1 (fr) * | 2017-10-26 | 2019-05-02 | Audi Ag | Système sur puce, procédé pour faire fonctionner un système sur puce et véhicule à moteur |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US8613087B2 (en) | 2010-12-06 | 2013-12-17 | Samsung Electronics Co., Ltd. | Computing system |
Family Cites Families (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR100383224B1 (ko) * | 2000-05-19 | 2003-05-12 | 주식회사 사이젠텍 | 리눅스 기반의 네트워크 통합 보안 시스템 및 그의 방법과이를 장착한 반도체 장치 |
| CN1489736A (zh) * | 2000-11-28 | 2004-04-14 | �����ĵ� | 用于维护和分发无线应用的方法和系统 |
| KR100557022B1 (ko) * | 2001-10-06 | 2006-03-03 | 주식회사 비즈모델라인 | 무선 바이러스 차단 방법 및 시스템 |
| KR20040090373A (ko) * | 2003-04-15 | 2004-10-22 | 주식회사 안철수연구소 | 무선 단말기에서 실시간 바이러스 감시/진단/치료 방법 |
| KR101359324B1 (ko) * | 2006-03-27 | 2014-02-24 | 텔레콤 이탈리아 소시에떼 퍼 아찌오니 | 이동 통신 장치상의 보안 정책 시행 방법 |
| KR101206542B1 (ko) * | 2006-12-18 | 2012-11-30 | 주식회사 엘지씨엔에스 | 하드웨어 기반의 동적공격 탐지 및 차단을 지원하는네트워크 보안 장치 및 방법 |
| KR100878895B1 (ko) * | 2007-02-08 | 2009-01-15 | 삼성전자주식회사 | 휴대단말 악성코드 처리장치 및 그 처리 방법 |
-
2009
- 2009-04-09 KR KR1020090030671A patent/KR101058301B1/ko not_active Expired - Fee Related
-
2010
- 2010-03-26 WO PCT/KR2010/001853 patent/WO2010117155A2/fr not_active Ceased
Cited By (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103679023A (zh) * | 2013-10-10 | 2014-03-26 | 南京邮电大学 | 一种联合计算架构下的海量病毒报告分析方法 |
| WO2019081270A1 (fr) * | 2017-10-26 | 2019-05-02 | Audi Ag | Système sur puce, procédé pour faire fonctionner un système sur puce et véhicule à moteur |
| US20200242276A1 (en) * | 2017-10-26 | 2020-07-30 | Audi Ag | Single-chip system, method for operating a single-chip system, and motor vehicle |
| US11783093B2 (en) | 2017-10-26 | 2023-10-10 | Audi Ag | Single-chip system, method for operating a single-chip system, and motor vehicle |
Also Published As
| Publication number | Publication date |
|---|---|
| KR101058301B1 (ko) | 2011-08-22 |
| WO2010117155A3 (fr) | 2011-01-20 |
| WO2010117155A9 (fr) | 2011-03-10 |
| KR20100112255A (ko) | 2010-10-19 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2010117153A2 (fr) | Appareil de détection de code malveillant à système sur puce, destiné à un dispositif mobile | |
| WO2010117152A2 (fr) | Détecteur de code malveillant à système sur puce et asic pour dispositif mobile | |
| RU2477520C1 (ru) | Система и способ динамической адаптации функционала антивирусного приложения на основе конфигурации устройства | |
| KR101279213B1 (ko) | 시스템 온 칩 기반의 안티-멀웨어 서비스를 제공할 수 있는 디바이스 및 그 방법과 인터페이스 방법 | |
| US20110314547A1 (en) | Anti-malware system and operating method thereof | |
| US20060236393A1 (en) | System and method for protecting a limited resource computer from malware | |
| CN111935061A (zh) | 一种工控主机的网络安全防护实现方法及工控主机 | |
| KR20070099201A (ko) | 휴대형 무선 기기의 보안 관리 방법 및 이를 이용한 보안관리 장치 | |
| CN101496025A (zh) | 用于向移动设备提供网络安全的系统和方法 | |
| WO2010048220A1 (fr) | Système et procédé de prévention des attaques et logiciels malveillants | |
| KR20080074271A (ko) | 휴대단말 악성코드 처리장치 및 그 처리 방법 | |
| WO2010117155A9 (fr) | Détecteur de code malveillant à système sur puce pour dispositif mobile | |
| CN104992116B (zh) | 基于intent sniffer的监测方法及系统 | |
| CN114338203B (zh) | 一种基于拟态蜜罐的内网检测系统及方法 | |
| WO2008050651A1 (fr) | Dispositif de communication, procédé de communication et programme de communication | |
| CN103139169A (zh) | 基于网络行为的病毒检测系统和方法 | |
| CN101340680B (zh) | 一种双核终端实现防毒和杀毒的方法和装置 | |
| WO2014168406A1 (fr) | Appareil et procédé permettant de diagnostiquer une attaque qui contourne des mécanismes de protection de mémoire | |
| WO2010117154A2 (fr) | Détecteur de code malveillant à système sur puce, et asic, pour dispositif mobile | |
| EP1897323B1 (fr) | Systeme et procede pour utiliser des reseaux de quarantaine afin de proteger des reseaux cellulaires par rapport a des virus et a des vers | |
| Ho et al. | Mobile and ubiquitous malware | |
| FI118709B (fi) | Menetelmä radioverkon päätelaitteen toiminnan seuraamiseksi, älykortti päätelaitteelle ja tunkeutumisen estojärjestelmä | |
| CN107786535A (zh) | 一种基于无线路由器的智能设备轻量级保护方法和无线路由器 | |
| CN111158736A (zh) | 一种智能捕获windows操作系统补丁更新文件的方法 | |
| CN111314307A (zh) | 物联网系统的安全防御方法、物联网系统及存储介质 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 10761816 Country of ref document: EP Kind code of ref document: A2 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 10761816 Country of ref document: EP Kind code of ref document: A2 |