会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 3. 发明授权
    • Malicious-process-determining method, data processing apparatus and recording medium
    • 恶意处理确定方法,数据处理装置和记录介质
    • US07827612B2
    • 2010-11-02
    • US11211735
    • 2005-08-26
    • Kazunori Saito
    • Kazunori Saito
    • G06F12/14
    • G06F21/563
    • A malicious-process-determining method, a data processing apparatus, and a recording medium according to the present invention each consists of reading the data stored in a buffer memory by one byte, and for a plurality of instruction sequences each having a different read address, sequentially analyzing what kind of instruction code is contained therein. When the int instruction is contained in the analyzed instruction sequence, the number of times the immediate value is pushed to the stack is greater than 1, and the character code corresponding to “/” is contained in the virtual stack, a determination is made that a malicious code is contained in the relevant instruction sequence.
    • 根据本发明的恶意处理确定方法,数据处理装置和记录介质各自包括将存储在缓冲存储器中的数据读取一个字节,并且对于多个指令序列,每个指令序列具有不同的读取地址 顺序地分析其中包含什么样的指令码。 当分析的指令序列中包含int指令时,立即值被推送到堆栈的次数大于1,并且对应于“/”的字符代码包含在虚拟堆栈中,确定 相关指令序列中包含恶意代码。
    • 4. 发明授权
    • Data processing method, data processing device computer program and recording medium
    • 数据处理方法,数据处理装置计算机程序和记录介质
    • US07805760B2
    • 2010-09-28
    • US10523690
    • 2003-08-04
    • Kazunori Saito
    • Kazunori Saito
    • G06F11/00G06F9/44G06F11/30
    • G06F21/566
    • The branch origin address and branch destination address of a branch instruction (jmp instruction) are stored, a judgment is made as to whether or not a call instruction for calling an instruction code group for executing an external command is associated with the branch destination address, a judgment is made as to whether or not the call destination address is between the branch origin address and the branch destination address if the call instruction is associated with the branch destination address, and information indicating that malicious code was detected is generated if the call destination of the call instruction is between the branch origin address and the branch destination address.
    • 存储分支指令(jmp指令)的分支起始地址和分支目的地地址,判定用于调用用于执行外部命令的指令代码组的调用指令是否与分支目的地地址相关联, 如果呼叫指示与分支目的地地址相关联,则判定呼叫目的地地址是否在分支起始地址和分支目的地地址之间,并且如果呼叫目的地产生了指示检测到恶意代码的信息 的呼叫指令位于分支起始地址和分支目的地址之间。