会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 1. 发明申请
    • SYSTEM AND METHOD FOR DETECTING MALICIOUS SCRIPT
    • 用于检测恶性症状的系统和方法
    • US20110239294A1
    • 2011-09-29
    • US12944100
    • 2010-11-11
    • Tae Ghyoon KIMYoung Han CHOISeok Jin CHOICheol Won LEE
    • Tae Ghyoon KIMYoung Han CHOISeok Jin CHOICheol Won LEE
    • G06F21/00
    • G06F21/563G06F21/566
    • Provided are a system and method for detecting a malicious script. The system includes a script decomposition module for decomposing a web page into scripts, a static analysis module for statically analyzing the decomposed scripts in the form of a document file, a dynamic analysis module for dynamically executing and analyzing the decomposed scripts, and a comparison module for comparing an analysis result of the static analysis module and an analysis result of the dynamic analysis module to determine whether the decomposed scripts are malicious scripts. The system and method can recognize a hidden dangerous hypertext markup language (HTML) tag irrespective of an obfuscation technique for hiding a malicious script in a web page and thus can cope with an unknown obfuscation technique.
    • 提供了用于检测恶意脚本的系统和方法。 该系统包括用于将网页分解成脚本的脚本分解模块,用于以文档文件的形式静态分析分解的脚本的静态分析模块,用于动态地执行和分析分解的脚本的动态分析模块,以及比较模块 用于比较静态分析模块的分析结果和动态分析模块的分析结果,以确定分解的脚本是否是恶意脚本。 系统和方法可以识别隐藏的危险超文本标记语言(HTML)标签,而不管用于在网页中隐藏恶意脚本的混淆技术,并且因此可以应对未知的混淆技术。
    • 7. 发明申请
    • PARTITION RECOVERY METHOD AND APPARATUS
    • 分区恢复方法和装置
    • US20110055163A1
    • 2011-03-03
    • US12626783
    • 2009-11-27
    • Hyun Uk HWANGKi Bom KIMTae Joo CHANGCheol Won LEE
    • Hyun Uk HWANGKi Bom KIMTae Joo CHANGCheol Won LEE
    • G06F17/30G06F12/16
    • G06F11/1435
    • Provided is a technology which searches an unallocated area to quickly extract information on a deleted partition when checking a disk and an evidence image in digital forensic, and adds a recovered partition to a forensic tool as a new partition. For this, the technology has direct access to the sector of a disk or an evidence image which is obtained, limits information search on an unallocated area only to an area satisfying the minimum size in which a partition may be created, changes an LBA-based sector access scheme into a CHS-based sector access scheme, and reads only the sector of a location having the possibility that a boot record exists to search information of a deleted partition, recovering a partition at high speed.
    • 提供了一种搜索未分配区域以在数字取证中检查磁盘和证据图像时快速提取关于删除的分区的信息的技术,并且将恢复的分区作为新的分区添加到取证工具。 为此,该技术可以直接访问所获得的磁盘或证据图像的扇区,仅在未分配区域上的信息搜索仅限于可以创建分区的满足最小大小的区域,改变基于LBA的 扇区访问方案转换为基于CHS的扇区访问方案,并且仅读取具有引导记录存在的可能性以搜索被删除的分区的信息的位置的扇区,以高速恢复分区。