会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 73. 发明申请
    • METHOD AND SYSTEM FOR MALICIOUS CODE DETECTION
    • 用于恶意代码检测的方法和系统
    • US20150058992A1
    • 2015-02-26
    • US14386932
    • 2013-03-20
    • BRITISH TELECOMMUNICATIONS public limited company
    • Fadi El-Moussa
    • H04L29/06
    • H04L63/145H04L63/1416
    • Embodiments of the invention are directed towards detecting and identifying malicious code injected into other legitimate web pages. The detection is divided into two processes. The first process is to detect a malicious code string within received web page code using a set of one or more criteria. The criteria include length of the string, as well as whether the string changes between received instances, and the status of the string within the web page code, particularly whether it is encapsulated between scripting tags, or otherwise indicated as being executable. The second process is based on using a proxy that will help in extracting and scanning the decrypted code against any malicious content. In particular, the second phase acts to remove the armour and evasion features that may be built into the malicious code, so that the code may then be inspected by the existing anti-virus or other host intrusion detection system (HIDS) present on the target system. Inspection may take place by dumping the memory contents to a file and then passing the file for inspection to the existing anti-virus or other HIDS.
    • 本发明的实施例旨在检测和识别注入到其他合法网页中的恶意代码。 检测分为两个过程。 第一个过程是使用一组或多个标准来检测所接收的网页代码中的恶意代码字符串。 标准包括字符串的长度以及字符串在接收的实例之间是否变化,以及网页代码中字符串的状态,特别是它是否被封装在脚本标签之间,或者以其他方式表示为可执行。 第二个过程是基于使用一个代理来帮助提取和扫描解密的代码,以防任何恶意内容。 特别地,第二阶段用于去除可能内置到恶意代码中的装甲和逃避特征,从而可以由存在于目标上的现有防病毒或其他主机入侵检测系统(HIDS)来检查代码 系统。 检查可能会通过将内存内容转储到文件中,然后将文件传递给现有的防病毒或其他HIDS。