WO2011002146A3 - Système et procédé pour détecter un programme malveillant - Google Patents
Système et procédé pour détecter un programme malveillant Download PDFInfo
- Publication number
- WO2011002146A3 WO2011002146A3 PCT/KR2010/002375 KR2010002375W WO2011002146A3 WO 2011002146 A3 WO2011002146 A3 WO 2011002146A3 KR 2010002375 W KR2010002375 W KR 2010002375W WO 2011002146 A3 WO2011002146 A3 WO 2011002146A3
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- malicious code
- api
- search target
- driver
- target driver
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/562—Static detection
- G06F21/563—Static detection by source code analysis
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F11/00—Error detection; Error correction; Monitoring
- G06F11/30—Monitoring
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Computer Hardware Design (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- Virology (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Quality & Reliability (AREA)
- Stored Programmes (AREA)
- Debugging And Monitoring (AREA)
Abstract
La présente invention concerne un système et un procédé permettant de détecter avec précision si un programme d'application arbitraire contient un programme malveillant par application d'une technique heuristique. Un système pour détecter un programme malveillant selon l'invention comprend un programme de recherche de pilote central, lequel programme de recherche sélectionner un pilote cible de recherche, un convertisseur de pilote central qui vérifie les fonctions API utilisées par le pilote cible de recherche, un programme d'analyse du pilote central qui détermine si une API de programme malveillant suspecte est contenue ou non dans les fonctions API utilisées par le pilote cible de recherche, et un programme d'analyse du programme malveillant qui désassemble l'API de programme malveillant suspecte utilisée par le pilote cible de recherche et une valeur de paramètre pour déterminer si l'API du programme malveillant suspectée est ou non une API de programme malveillant.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR10-2009-0058960 | 2009-06-30 | ||
| KR1020090058960A KR101161008B1 (ko) | 2009-06-30 | 2009-06-30 | 악성코드 탐지시스템 및 방법 |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| WO2011002146A2 WO2011002146A2 (fr) | 2011-01-06 |
| WO2011002146A3 true WO2011002146A3 (fr) | 2011-02-17 |
Family
ID=43411537
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/KR2010/002375 Ceased WO2011002146A2 (fr) | 2009-06-30 | 2010-04-16 | Système et procédé pour détecter un programme malveillant |
Country Status (2)
| Country | Link |
|---|---|
| KR (1) | KR101161008B1 (fr) |
| WO (1) | WO2011002146A2 (fr) |
Families Citing this family (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR101206853B1 (ko) * | 2011-06-23 | 2012-11-30 | 주식회사 잉카인터넷 | 네트워크 접근 제어시스템 및 방법 |
| CN103186740B (zh) * | 2011-12-27 | 2015-09-23 | 北京大学 | 一种Android恶意软件的自动化检测方法 |
| KR101404882B1 (ko) * | 2013-01-24 | 2014-06-11 | 주식회사 이스트시큐리티 | 행위를 기반으로 한 악성코드 분류시스템 및 분류방법 |
| CN103150513B (zh) * | 2013-03-20 | 2015-12-09 | 北京奇虎科技有限公司 | 拦截应用程序中的植入信息的方法及装置 |
| US10242200B1 (en) * | 2015-03-06 | 2019-03-26 | Tripwire, Inc. | Static analysis of vulnerabilities in application packages |
| KR101724412B1 (ko) * | 2015-09-23 | 2017-04-10 | 한국전자통신연구원 | 확장 코드를 이용한 어플리케이션 분석 장치 및 방법 |
| CN116049814A (zh) * | 2022-12-27 | 2023-05-02 | 安天科技集团股份有限公司 | 建立信息安全防护的方法、装置、存储介质及电子设备 |
Citations (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2001025870A2 (fr) * | 1999-10-01 | 2001-04-12 | Infraworks Corporation | Systeme et procede permettant de securiser les donnees |
| WO2004003710A1 (fr) * | 2002-06-27 | 2004-01-08 | Koninklijke Philips Electronics N.V. | Processeur de securite a configuration de bus |
| KR20040080845A (ko) * | 2003-03-14 | 2004-09-20 | 주식회사 안철수연구소 | 코드 삽입 기법을 이용한 악성 스크립트 감지 방법 |
| KR20040083409A (ko) * | 2004-09-10 | 2004-10-01 | (주) 세이프아이 | 실시간 감시를 통한 컴퓨터 보호 방법 및 이에 따라보호되는 컴퓨터와 그 시스템 |
| US20060021054A1 (en) * | 2004-07-21 | 2006-01-26 | Microsoft Corporation | Containment of worms |
| KR100628869B1 (ko) * | 2004-12-14 | 2006-09-27 | 한국전자통신연구원 | 악성 코드가 숨겨진 오피스 문서 탐지장치 및 그 방법 |
| KR100666562B1 (ko) * | 2005-08-11 | 2007-01-09 | 주식회사 웨어플러스 | 커널 드라이버 및 프로세스 보호 방법 |
| KR20090025146A (ko) * | 2007-09-05 | 2009-03-10 | 라이오닉 코포레이션 | 웹 페이지 공격을 방지하기 위한 방법 및 장치 |
-
2009
- 2009-06-30 KR KR1020090058960A patent/KR101161008B1/ko not_active Expired - Fee Related
-
2010
- 2010-04-16 WO PCT/KR2010/002375 patent/WO2011002146A2/fr not_active Ceased
Patent Citations (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2001025870A2 (fr) * | 1999-10-01 | 2001-04-12 | Infraworks Corporation | Systeme et procede permettant de securiser les donnees |
| WO2004003710A1 (fr) * | 2002-06-27 | 2004-01-08 | Koninklijke Philips Electronics N.V. | Processeur de securite a configuration de bus |
| KR20040080845A (ko) * | 2003-03-14 | 2004-09-20 | 주식회사 안철수연구소 | 코드 삽입 기법을 이용한 악성 스크립트 감지 방법 |
| US20060021054A1 (en) * | 2004-07-21 | 2006-01-26 | Microsoft Corporation | Containment of worms |
| KR20040083409A (ko) * | 2004-09-10 | 2004-10-01 | (주) 세이프아이 | 실시간 감시를 통한 컴퓨터 보호 방법 및 이에 따라보호되는 컴퓨터와 그 시스템 |
| KR100628869B1 (ko) * | 2004-12-14 | 2006-09-27 | 한국전자통신연구원 | 악성 코드가 숨겨진 오피스 문서 탐지장치 및 그 방법 |
| KR100666562B1 (ko) * | 2005-08-11 | 2007-01-09 | 주식회사 웨어플러스 | 커널 드라이버 및 프로세스 보호 방법 |
| KR20090025146A (ko) * | 2007-09-05 | 2009-03-10 | 라이오닉 코포레이션 | 웹 페이지 공격을 방지하기 위한 방법 및 장치 |
Also Published As
| Publication number | Publication date |
|---|---|
| KR101161008B1 (ko) | 2012-07-02 |
| KR20110001426A (ko) | 2011-01-06 |
| WO2011002146A2 (fr) | 2011-01-06 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2011002146A3 (fr) | Système et procédé pour détecter un programme malveillant | |
| WO2011151736A3 (fr) | Procédé et appareil pour analyser et détecter des logiciels malveillants | |
| WO2009091487A3 (fr) | Détection de codes malveillants avec pistage d'altérations | |
| WO2009149051A3 (fr) | Corrélation adaptative | |
| WO2011055945A3 (fr) | Appareil et procédé pour détecter des sites malveillants | |
| WO2011037665A3 (fr) | Procédés et appareil pour chemin sécurisé vérifiable par l'utilisateur en présence d'un logiciel malveillant | |
| WO2013070756A3 (fr) | Système et procédé de traitement d'échantillons | |
| WO2011112347A3 (fr) | Système et procédé de détection de logiciel malveillant | |
| WO2014078585A3 (fr) | Procédés, systèmes et supports lisibles par ordinateur pour détecter des attaques d'injection de commandes | |
| WO2012115956A3 (fr) | Systèmes et procédés consistant à utiliser un dispositif informatique comportant un noyau du système d'exploitation sécurisé | |
| MY165418A (en) | System and method for detection of malware | |
| DE602007013524D1 (de) | Erkennung und vorhersage von frühgeburten | |
| WO2013171747A3 (fr) | Procédé d'identification d'une entrée de paume sur un numériseur | |
| EP2472425A3 (fr) | Système et procédé de détection de malveillance inconnue | |
| EP2426580A3 (fr) | Appareil de traitement d'informations, procédé de contrôle d'entrée de l'appareil de traitement d'informations et programme | |
| WO2007058882A3 (fr) | Procede et appareil pour detecter et empecher un comportement non sur de programmes javascript | |
| AU2013211850A8 (en) | Methods for profiling and quantitating cell-free RNA | |
| WO2011159537A3 (fr) | Procédé et dispositif pour la détection d'analytes | |
| WO2011047296A3 (fr) | Détection d'un logiciel malveillant, et réponse à celui-ci, à l'aide de fichiers liens | |
| MX369610B (es) | Metodos, dispositivos y sistemas para analisis de muestras. | |
| WO2013073999A8 (fr) | Procédé d'analyse automatisée de documents textuels | |
| WO2013090386A3 (fr) | Procédés et ensembles pour détection in situ à température ambiante d'un acide nucléique cible dans un échantillon biologique | |
| BR102013017772B8 (pt) | Dispositivo e método para detecção de contaminantes metálicos em um produto | |
| WO2012082742A3 (fr) | Détection du cancer par des anticorps anti-ccl25 et anti-ccr9 | |
| WO2012034130A3 (fr) | Procédés et compositions pour la détection d'acides nucléiques |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 10794281 Country of ref document: EP Kind code of ref document: A2 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 10794281 Country of ref document: EP Kind code of ref document: A2 |