会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 2. 发明申请
    • APPARATUS AND METHOD OF DETECTING FILE HAVING EMBEDDED MALICIOUS CODE
    • 检测具有嵌入式恶意代码的文件的装置和方法
    • US20080115219A1
    • 2008-05-15
    • US11780303
    • 2007-07-19
    • Yun-Ju KIMYoungtae YUN
    • Yun-Ju KIMYoungtae YUN
    • G06F11/00
    • G06F21/563
    • An apparatus and method of detecting a file having an embedded malicious code by confirming normality/abnormality of a process that operates in a file process is disclosed. The apparatus includes an execution code detection module for detecting whether an executable file format is included in a file to be inspected through a static analysis, a support program searching module for searching for a support program according to an extension of the file to be inspected and reporting a corresponding process name and an execution path, an abnormal process detection nodule for monitoring the searched support process and judging whether a parent process of a newly created process is normal using a tree structure of the process, and an abnormal process compulsory ending module for compulsorily ending the newly created process if it is judged that the file to be inspected is the file having the embedded malicious code. Accordingly, execution of all abnormal processes can be checked.
    • 公开了一种通过确认在文件处理中操作的处理的正常/异常来检测具有嵌入式恶意代码的文件的装置和方法。 该装置包括:执行代码检测模块,用于通过静态分析检测可执行文件格式是否包括在待检查的文件中;支持程序搜索模块,用于根据待检查的文件的扩展来搜索支持程序, 报告对应的进程名称和执行路径,用于监视所搜索的支持处理的异常处理检测结点,并使用该进程的树结构判断新创建的进程的父进程是否正常;以及异常处理强制结束模块, 如果判断要检查的文件是具有嵌入的恶意代码的文件,则强制结束新创建的进程。 因此,可以检查所有异常处理的执行。
    • 7. 发明授权
    • Apparatus and method for detecting malicious process
    • 恶意程序检测装置及方法
    • US08091133B2
    • 2012-01-03
    • US12103794
    • 2008-04-16
    • Yun Ju KimYoung Tae Yun
    • Yun Ju KimYoung Tae Yun
    • G06F11/00G06F12/14G06F12/16G08B23/00G06F9/455
    • G06F21/56
    • Provided are an apparatus and method for detecting a malicious process. The apparatus includes: a process monitoring unit for monitoring a process generated in a computing environment; a target process setting unit for previously setting a test target process among the processes confirmed by the process monitoring unit; a process generation time change monitoring unit for monitoring if the target process set by the target process setting unit requests to change a generation time; a generation time change preventing unit for preventing a change in the generation time of the target process when the target process requests to change the generation time; and a malicious process detecting unit for determining that a child process of the target process set by the target process setting unit is a malicious process if the child process is generated within a predetermined reference time.
    • 提供了用于检测恶意进程的装置和方法。 该装置包括:用于监视在计算环境中生成的处理的过程监视单元; 目标处理设定单元,用于在由处理监视单元确认的处理中预先设置测试对象处理; 过程生成时间变化监视单元,用于监视由目标处理设置单元设置的目标处理是否请求改变生成时间; 当所述目标处理请求改变所述生成时间时,用于防止所述目标处理的生成时间的改变的生成时间改变防止单元; 以及恶意处理检测单元,用于如果在预定参考时间内生成子进程,则确定由目标处理设置单元设置的目标进程的子进程是恶意进程。
    • 8. 发明申请
    • DEVICE AND METHOD FOR BLOCKING AUTORUN OF MALICIOUS CODE
    • 阻止恶意代码自动化的装置和方法
    • US20090138969A1
    • 2009-05-28
    • US12209361
    • 2008-09-12
    • Yun Ju KimYoung Tae Yun
    • Yun Ju KimYoung Tae Yun
    • G06F21/06
    • G06F21/51
    • A device and method for blocking autorun of a malicious code through an autorun file stored in a removable storage device are provided. A device manager monitors a connection of a removable storage device, acquires a global unique identifier of the removable storage device, and deletes an autorun file for running the malicious code from the removable storage. A registry manager determines whether a registry key for storing content of the autorun file is generated using the global unique identifier of the removable storage device and deletes the registry key. The present invention can block autorun of a malicious code stored in the removable storage device by retrieving and deleting a registry key for performing the autorun technique when a removable storage device is connected to a system.
    • 提供了通过存储在可移动存储设备中的自动运行文件来阻止恶意代码自动运行的装置和方法。 设备管理器监视可移动存储设备的连接,获取可移动存储设备的全局唯一标识符,并从可移动存储器中删除用于运行恶意代码的自动运行文件。 注册管理器管理器确定是否使用可移动存储设备的全局唯一标识符生成用于存储自动运行文件的内容的注册表项,并删除注册表项。 本发明可以通过检索和删除用于在可移动存储设备连接到系统时执行自动运行技术的注册表项来阻止存储在可移动存储设备中的恶意代码的自动运行。
    • 9. 发明申请
    • APPARATUS AND METHOD FOR DETECTING MALICIOUS PROCESS
    • 检测恶性程序的装置和方法
    • US20090070876A1
    • 2009-03-12
    • US12103794
    • 2008-04-16
    • Yun Ju KIMYoung Tae YUN
    • Yun Ju KIMYoung Tae YUN
    • G06F11/00
    • G06F21/56
    • Provided are an apparatus and method for detecting a malicious process. The apparatus includes: a process monitoring unit for monitoring a process generated in a computing environment; a target process setting unit for previously setting a test target process among the processes confirmed by the process monitoring unit; a process generation time change monitoring unit for monitoring if the target process set by the target process setting unit requests to change a generation time; a generation time change preventing unit for preventing a change in the generation time of the target process when the target process requests to change the generation time; and a malicious process detecting unit for determining that a child process of the target process set by the target process setting unit is a malicious process if the child process is generated within a predetermined reference time.
    • 提供了用于检测恶意进程的装置和方法。 该装置包括:用于监视在计算环境中生成的处理的过程监视单元; 目标处理设定单元,用于在由处理监视单元确认的处理中预先设置测试对象处理; 过程生成时间变化监视单元,用于监视由目标处理设置单元设置的目标处理是否请求改变生成时间; 当所述目标处理请求改变所述生成时间时,用于防止所述目标处理的生成时间的改变的生成时间改变防止单元; 以及恶意处理检测单元,用于如果在预定参考时间内生成子进程,则确定由目标处理设置单元设置的目标进程的子进程是恶意进程。