WO2011002146A3 - Système et procédé pour détecter un programme malveillant - Google Patents

Système et procédé pour détecter un programme malveillant Download PDF

Info

Publication number
WO2011002146A3
WO2011002146A3 PCT/KR2010/002375 KR2010002375W WO2011002146A3 WO 2011002146 A3 WO2011002146 A3 WO 2011002146A3 KR 2010002375 W KR2010002375 W KR 2010002375W WO 2011002146 A3 WO2011002146 A3 WO 2011002146A3
Authority
WO
WIPO (PCT)
Prior art keywords
malicious code
api
search target
driver
target driver
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/KR2010/002375
Other languages
English (en)
Korean (ko)
Other versions
WO2011002146A2 (fr
Inventor
김윤동
서성원
연성호
이지남
정영석
한명호
최재영
이재홍
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Inca Internet Co Ltd
Original Assignee
Inca Internet Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Inca Internet Co Ltd filed Critical Inca Internet Co Ltd
Publication of WO2011002146A2 publication Critical patent/WO2011002146A2/fr
Publication of WO2011002146A3 publication Critical patent/WO2011002146A3/fr
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/56Computer malware detection or handling, e.g. anti-virus arrangements
    • G06F21/562Static detection
    • G06F21/563Static detection by source code analysis
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/56Computer malware detection or handling, e.g. anti-virus arrangements
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/30Monitoring

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • General Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • Computer Hardware Design (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Virology (AREA)
  • Health & Medical Sciences (AREA)
  • General Health & Medical Sciences (AREA)
  • Quality & Reliability (AREA)
  • Stored Programmes (AREA)
  • Debugging And Monitoring (AREA)

Abstract

La présente invention concerne un système et un procédé permettant de détecter avec précision si un programme d'application arbitraire contient un programme malveillant par application d'une technique heuristique. Un système pour détecter un programme malveillant selon l'invention comprend un programme de recherche de pilote central, lequel programme de recherche sélectionner un pilote cible de recherche, un convertisseur de pilote central qui vérifie les fonctions API utilisées par le pilote cible de recherche, un programme d'analyse du pilote central qui détermine si une API de programme malveillant suspecte est contenue ou non dans les fonctions API utilisées par le pilote cible de recherche, et un programme d'analyse du programme malveillant qui désassemble l'API de programme malveillant suspecte utilisée par le pilote cible de recherche et une valeur de paramètre pour déterminer si l'API du programme malveillant suspectée est ou non une API de programme malveillant.
PCT/KR2010/002375 2009-06-30 2010-04-16 Système et procédé pour détecter un programme malveillant Ceased WO2011002146A2 (fr)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
KR10-2009-0058960 2009-06-30
KR1020090058960A KR101161008B1 (ko) 2009-06-30 2009-06-30 악성코드 탐지시스템 및 방법

Publications (2)

Publication Number Publication Date
WO2011002146A2 WO2011002146A2 (fr) 2011-01-06
WO2011002146A3 true WO2011002146A3 (fr) 2011-02-17

Family

ID=43411537

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/KR2010/002375 Ceased WO2011002146A2 (fr) 2009-06-30 2010-04-16 Système et procédé pour détecter un programme malveillant

Country Status (2)

Country Link
KR (1) KR101161008B1 (fr)
WO (1) WO2011002146A2 (fr)

Families Citing this family (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR101206853B1 (ko) * 2011-06-23 2012-11-30 주식회사 잉카인터넷 네트워크 접근 제어시스템 및 방법
CN103186740B (zh) * 2011-12-27 2015-09-23 北京大学 一种Android恶意软件的自动化检测方法
KR101404882B1 (ko) * 2013-01-24 2014-06-11 주식회사 이스트시큐리티 행위를 기반으로 한 악성코드 분류시스템 및 분류방법
CN103150513B (zh) * 2013-03-20 2015-12-09 北京奇虎科技有限公司 拦截应用程序中的植入信息的方法及装置
US10242200B1 (en) * 2015-03-06 2019-03-26 Tripwire, Inc. Static analysis of vulnerabilities in application packages
KR101724412B1 (ko) * 2015-09-23 2017-04-10 한국전자통신연구원 확장 코드를 이용한 어플리케이션 분석 장치 및 방법
CN116049814A (zh) * 2022-12-27 2023-05-02 安天科技集团股份有限公司 建立信息安全防护的方法、装置、存储介质及电子设备

Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2001025870A2 (fr) * 1999-10-01 2001-04-12 Infraworks Corporation Systeme et procede permettant de securiser les donnees
WO2004003710A1 (fr) * 2002-06-27 2004-01-08 Koninklijke Philips Electronics N.V. Processeur de securite a configuration de bus
KR20040080845A (ko) * 2003-03-14 2004-09-20 주식회사 안철수연구소 코드 삽입 기법을 이용한 악성 스크립트 감지 방법
KR20040083409A (ko) * 2004-09-10 2004-10-01 (주) 세이프아이 실시간 감시를 통한 컴퓨터 보호 방법 및 이에 따라보호되는 컴퓨터와 그 시스템
US20060021054A1 (en) * 2004-07-21 2006-01-26 Microsoft Corporation Containment of worms
KR100628869B1 (ko) * 2004-12-14 2006-09-27 한국전자통신연구원 악성 코드가 숨겨진 오피스 문서 탐지장치 및 그 방법
KR100666562B1 (ko) * 2005-08-11 2007-01-09 주식회사 웨어플러스 커널 드라이버 및 프로세스 보호 방법
KR20090025146A (ko) * 2007-09-05 2009-03-10 라이오닉 코포레이션 웹 페이지 공격을 방지하기 위한 방법 및 장치

Patent Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2001025870A2 (fr) * 1999-10-01 2001-04-12 Infraworks Corporation Systeme et procede permettant de securiser les donnees
WO2004003710A1 (fr) * 2002-06-27 2004-01-08 Koninklijke Philips Electronics N.V. Processeur de securite a configuration de bus
KR20040080845A (ko) * 2003-03-14 2004-09-20 주식회사 안철수연구소 코드 삽입 기법을 이용한 악성 스크립트 감지 방법
US20060021054A1 (en) * 2004-07-21 2006-01-26 Microsoft Corporation Containment of worms
KR20040083409A (ko) * 2004-09-10 2004-10-01 (주) 세이프아이 실시간 감시를 통한 컴퓨터 보호 방법 및 이에 따라보호되는 컴퓨터와 그 시스템
KR100628869B1 (ko) * 2004-12-14 2006-09-27 한국전자통신연구원 악성 코드가 숨겨진 오피스 문서 탐지장치 및 그 방법
KR100666562B1 (ko) * 2005-08-11 2007-01-09 주식회사 웨어플러스 커널 드라이버 및 프로세스 보호 방법
KR20090025146A (ko) * 2007-09-05 2009-03-10 라이오닉 코포레이션 웹 페이지 공격을 방지하기 위한 방법 및 장치

Also Published As

Publication number Publication date
KR101161008B1 (ko) 2012-07-02
KR20110001426A (ko) 2011-01-06
WO2011002146A2 (fr) 2011-01-06

Similar Documents

Publication Publication Date Title
WO2011002146A3 (fr) Système et procédé pour détecter un programme malveillant
WO2011151736A3 (fr) Procédé et appareil pour analyser et détecter des logiciels malveillants
WO2009091487A3 (fr) Détection de codes malveillants avec pistage d'altérations
WO2009149051A3 (fr) Corrélation adaptative
WO2011055945A3 (fr) Appareil et procédé pour détecter des sites malveillants
WO2011037665A3 (fr) Procédés et appareil pour chemin sécurisé vérifiable par l'utilisateur en présence d'un logiciel malveillant
WO2013070756A3 (fr) Système et procédé de traitement d'échantillons
WO2011112347A3 (fr) Système et procédé de détection de logiciel malveillant
WO2014078585A3 (fr) Procédés, systèmes et supports lisibles par ordinateur pour détecter des attaques d'injection de commandes
WO2012115956A3 (fr) Systèmes et procédés consistant à utiliser un dispositif informatique comportant un noyau du système d'exploitation sécurisé
MY165418A (en) System and method for detection of malware
DE602007013524D1 (de) Erkennung und vorhersage von frühgeburten
WO2013171747A3 (fr) Procédé d'identification d'une entrée de paume sur un numériseur
EP2472425A3 (fr) Système et procédé de détection de malveillance inconnue
EP2426580A3 (fr) Appareil de traitement d'informations, procédé de contrôle d'entrée de l'appareil de traitement d'informations et programme
WO2007058882A3 (fr) Procede et appareil pour detecter et empecher un comportement non sur de programmes javascript
AU2013211850A8 (en) Methods for profiling and quantitating cell-free RNA
WO2011159537A3 (fr) Procédé et dispositif pour la détection d'analytes
WO2011047296A3 (fr) Détection d'un logiciel malveillant, et réponse à celui-ci, à l'aide de fichiers liens
MX369610B (es) Metodos, dispositivos y sistemas para analisis de muestras.
WO2013073999A8 (fr) Procédé d'analyse automatisée de documents textuels
WO2013090386A3 (fr) Procédés et ensembles pour détection in situ à température ambiante d'un acide nucléique cible dans un échantillon biologique
BR102013017772B8 (pt) Dispositivo e método para detecção de contaminantes metálicos em um produto
WO2012082742A3 (fr) Détection du cancer par des anticorps anti-ccl25 et anti-ccr9
WO2012034130A3 (fr) Procédés et compositions pour la détection d'acides nucléiques

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 10794281

Country of ref document: EP

Kind code of ref document: A2

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 10794281

Country of ref document: EP

Kind code of ref document: A2