$\require{mediawiki-texvc}$

연합인증

연합인증 가입 기관의 연구자들은 소속기관의 인증정보(ID와 암호)를 이용해 다른 대학, 연구기관, 서비스 공급자의 다양한 온라인 자원과 연구 데이터를 이용할 수 있습니다.

이는 여행자가 자국에서 발행 받은 여권으로 세계 각국을 자유롭게 여행할 수 있는 것과 같습니다.

연합인증으로 이용이 가능한 서비스는 NTIS, DataON, Edison, Kafe, Webinar 등이 있습니다.

한번의 인증절차만으로 연합인증 가입 서비스에 추가 로그인 없이 이용이 가능합니다.

다만, 연합인증을 위해서는 최초 1회만 인증 절차가 필요합니다. (회원이 아닐 경우 회원 가입이 필요합니다.)

연합인증 절차는 다음과 같습니다.

최초이용시에는
ScienceON에 로그인 → 연합인증 서비스 접속 → 로그인 (본인 확인 또는 회원가입) → 서비스 이용

그 이후에는
ScienceON 로그인 → 연합인증 서비스 접속 → 서비스 이용

연합인증을 활용하시면 KISTI가 제공하는 다양한 서비스를 편리하게 이용하실 수 있습니다.

Application behavior based malware detection 원문보기

IPC분류정보
국가/구분 United States(US) Patent 등록
국제특허분류(IPC7판)
  • G06F-021/00
출원번호 UP-0247349 (2005-10-11)
등록번호 US-7779472 (2010-09-06)
발명자 / 주소
  • Lou, Vic
출원인 / 주소
  • Trend Micro, Inc.
대리인 / 주소
    Beyer Law Group LLP
인용정보 피인용 횟수 : 79  인용 특허 : 10

초록

An executable file is loaded into a virtual machine arranged to emulate the instructions of said executable file. The virtual machine keeps track of application programming interfaces (APIs) used by the executable file during emulation. The executable file is scanned to determine names of (APIs) use

대표청구항

I claim: 1. A method of detecting malware comprising: receiving a suspect executable computer file at a computer; loading said executable file into a virtual machine arranged to emulate instructions of said executable file; emulating said instructions of said executable file using said virtual mach

이 특허에 인용된 특허 (10)

  1. Qin,Simon, Backup/recovery system and methods for protecting a computer system.
  2. Arnold,William C.; Chess,David M.; Morar,John F.; Segal,Alla; Whalley,Ian N.; White,Steve R., Method and apparatus for determination of the non-replicative behavior of a malicious program.
  3. Saika,Nobuyuki, Method and program for creating a snapshot, and storage system.
  4. Kouznetsov,Victor; Libenzi,Davide; Fallenstedt,Martin; Palmer,David W.; Pak,Michael C., Platform abstraction layer for a wireless malware scanning engine.
  5. Kouznetsov, Victor, System and method for dynamically detecting computer viruses through associative behavioral analysis of runtime state.
  6. Fairweather,John, System and method for managing collections of data on a network.
  7. Marinescu,Adrian M., System and method for proactive computer virus protection.
  8. Ho,Chih Kun; Lo,Chien Ping, System and method having an antivirus virtual scanning processor with plug-in functionalities.
  9. Horvitz Eric ; Heckerman David E. ; Dumais Susan T. ; Sahami Mehran ; Platt John C., Technique which utilizes a probabilistic classifier to detect "junk" e-mail by automatically updating a training and re-training the classifier based on the updated training set.
  10. Moody,Joseph R.; Gaddini,Joseph D., Vertical fore grip with bipod.

이 특허를 인용한 특허 (79)

  1. Gnesda, Nicholas; Salunke, Abhay, Adaptive integrity validation for portable information handling systems.
  2. Kim, Hyun Joo; Kim, Jong Hyun; Kim, Ik Kyun, Apparatus and method for detecting malware code by generating and analyzing behavior pattern.
  3. Kureha, Toshinari; Nouri, Koorosh; Do, Arthur; Chess, Brian; Thornton, Roger, Apparatus and method for performing dynamic security testing using static analysis data.
  4. Kim, Yo Sik; Noh, Sang Kyun; Chung, Yoon Jung; Kim, Dong Soo; Kim, Won Ho; Han, Yu Jung; Yun, Young Tae; Sohn, Ki Wook; Lee, Cheol Won, Apparatus, system and method for detecting malicious code.
  5. Kalinichenko, Michael, Application of nested behavioral rules for anti-malware processing.
  6. Wysopal, Christopher J.; Moynahan, Matthew P.; Stevenson, Jon R., Assessment and analysis of software security flaws in virtual machines.
  7. Titonis, Theodora Heather; Manohar-Alers, Nelson Roberto; Wysopal, Christopher John, Automated behavioral and static analysis using an instrumented sandbox and machine learning classification for mobile security.
  8. Huang, Wayne; Idle, M. James, Behavior profiling for malware detection.
  9. Salsamendi, Ryan C.; Seger, Robert A., Collecting algorithmically generated domains.
  10. Salsamendi, Ryan C.; Xu, Wei, Deduplicating malware.
  11. Srivastava, Kumar S., Detecting a compromised online user account.
  12. Chen, Joseph H.; Chen, Zhongning, Detecting and remediating malware dropped by files.
  13. Chen, Joseph H.; Chen, Zhongning, Detecting and remediating malware dropped by files.
  14. Franklin, Douglas North, Detecting malicious software.
  15. Franklin, Douglas North, Detecting malicious software.
  16. Franklin, Douglas North, Detecting malicious software.
  17. Qu, Bo; Wang, Xinran; Sanders, Kyle, Detecting malware.
  18. Mann, Uriel, Detection of malicious script operations using statistical analysis.
  19. Lu, ChienHua; Qu, Bo, Detection of malware using an instrumented virtual machine environment.
  20. Liu, Jiangxia; Ouyang, Xin; Qu, Bo, Dynamic malware analysis of a URL using a browser executed in an instrumented virtual machine environment.
  21. Goodman, Robert F.; Gretzinger, Michael R.; Burkhardt, John R.; Schiff, Rachel R.; Claydon, Barnaby M.; Rae, Katherine W.; Sturtevant, Reed P., Email characterization.
  22. Wang, Xinran; Xie, Huagang, Evaluating malware in a virtual machine using copy-on-write.
  23. Wang, Xinran; Xie, Huagang, Evaluating malware in a virtual machine using dynamic patching.
  24. Wang, Xinran; Xie, Huagang, Evaluating malware in a virtual machine using dynamic patching.
  25. Thioux, Emmanuel; Amin, Muhammad; Ismael, Osman, File extraction from memory dump for malicious content analysis.
  26. Wang, Xinran; Xie, Huagang, Heuristic botnet detection.
  27. Sethumadhavan, Lakshminarasimhan; Waksman, Adam; Suozzo, Matthew, Identification of backdoors and backdoor triggers.
  28. Zuk, Nir; Lazzarato, Renzo; Xie, Huagang, Identification of malware sites using unknown URL sites and newly registered DNS addresses.
  29. Colvin, Ryan Charles; Haber, Elliott Jeb; Bhatawdekar, Ameya; Penta, Anthony P., Identifying application reputation based on resource accesses.
  30. Bettini, Anthony John; Watkins, Kevin; Guerra, Domingo J.; Price, Michael, In-line filtering of insecure or unwanted mobile device software components or communications.
  31. Suominen, Mikko, Malware detection.
  32. Wang, Xinran; Xie, Huagang; Sanders, Kyle, Malware detection based on traffic analysis.
  33. Osipkov, Ivan; Jiang, Wei; Davis, Malcolm Hollis; Hines, Douglas; Korb, Joshua, Message categorization.
  34. Osipkov, Ivan; Jiang, Wei; Davis, Malcolm Hollis; Hines, Douglas; Korb, Joshua, Message categorization.
  35. Osipkov, Ivan; Jiang, Wei; Davis, Malcolm Hollis; Hines, Douglas; Korb, Joshua, Message categorization.
  36. Abdel-Aziz, Bassem; Chow, Stanley Taihai; Chen, Shu-Lin, Method and apparatus for detecting malware.
  37. Li, Wei; Tong, Yongliang, Method and apparatus for determining malicious program.
  38. Krishnappa, Bhaskar, Method and system for minimizing the effects of rogue security software.
  39. Wang, Peng; Yun, Peng, Method, system, and apparatus for detecting malicious code.
  40. Kriegsman, Mark; Black, Brian, Methods and systems for providing feedback and suggested programming methods.
  41. Eskin, Eleazar; Arnold, Andrew; Prerau, Michael; Portnoy, Leonid; Stolfo, Salvatore J., Methods of unsupervised anomaly detection using a geometric framework.
  42. Bettini, Anthony John; Watkins, Kevin; Guerra, Domingo J.; Price, Michael, Off-device anti-malware protection for mobile devices.
  43. Bettini, Anthony John; Watkins, Kevin; Guerra, Domingo J.; Price, Michael, Off-device anti-malware protection for mobile devices.
  44. Sharma, Babita; Duer, Kristofer Alyn; Goldberg, Richard Myer; Teilhet, Stephen Darwin; Turnham, Jeffrey Charles; Wang, Shu; Xiao, Hua, Prioritizing security findings in a SAST tool based on historical security analysis.
  45. Bettini, Anthony John; Watkins, Kevin; Guerra, Domingo J.; Price, Michael, Quantifying the risks of applications for mobile devices.
  46. Bettini, Anthony John; Watkins, Kevin; Guerra, Domingo J.; Price, Michael, Quantifying the risks of applications for mobile devices.
  47. Zuo, Wei; Wu, Weimin; Shen, Tao, Reduction of false positives in malware detection using file property analysis.
  48. Grystan, Volodymyr; Tumoyan, Evgeny; Romanenko, Ivan; Kukoba, Anton; Sviridenkov, Anatolii; Evgenyevich, Rusin Dmitry, Robust malware detector.
  49. Rioux, Christien, Software analysis framework.
  50. Davis, Aaron R.; Aldrich, Timothy M.; Bialek, Matthew S.; Lemm, Timothy M.; Kospiah, Shaun, Software network behavior analysis and identification system.
  51. Martini, Paul Michael; Martini, Peter Anthony, Software program identification based on program behavior.
  52. Martini, Paul Michael; Martini, Peter Anthony, Software program identification based on program behavior.
  53. Thioux, Emmanuel; Amin, Muhammad; Ismael, Osman Abdoul, System and method for analysis of a memory dump associated with a potentially malicious content suspect.
  54. Kim, Tae Ghyoon; Choi, Young Han; Choi, Seok Jin; Lee, Cheol Won, System and method for detecting malicious script.
  55. Golovkin, Maxim Y., System and method for detecting unknown packers and cryptors.
  56. Monastyrsky, Alexey V.; Butuzov, Vitaly V.; Golovkin, Maxim Y.; Karasovsky, Dmitry V.; Pintiysky, Vladislav V.; Kobychev, Denis Y., System and method of performing an antivirus scan of a file on a virtual machine.
  57. Honig, Andrew; Howard, Andrew; Eskin, Eleazar; Stolfo, Salvatore J., System and methods for adaptive model generation for detecting intrusion in computer systems.
  58. Honig, Andrew; Howard, Andrew; Eskin, Eleazar; Stolfo, Salvatore J., System and methods for adaptive model generation for detecting intrusion in computer systems.
  59. Stolfo, Salvatore J.; Eskin, Eleazar; Herskop, Shlomo; Bhattacharyya, Manasi, System and methods for detecting malicious email transmission.
  60. Lomont, Chris C.; Jacobus, Charles J., System and methods for detecting software vulnerabilities and malicious code.
  61. Honig, Andrew; Howard, Andrew; Eskin, Eleazar; Stolfo, Salvatore J., Systems and methods for adaptive model generation for detecting intrusions in computer systems.
  62. Crofton, Teo Winton; Baker, Clark Marshall, Systems and methods for automatic detection of malicious activity via common files.
  63. Crofton, Teo Winton; Baker, Clark Marshall, Systems and methods for automatic snapshotting of backups based on malicious modification detection.
  64. Kane, David, Systems and methods for automatically blacklisting an internet domain based on the activities of an application.
  65. Mohaisen, Aziz; Alrawi, Omar; Larson, Matthew, Systems and methods for behavior-based automated malware analysis and classification.
  66. McCorkendale, Bruce; Gong, Sheng; Hu, Wei Guo Eric; Huang, Ge Hua; Mao, Jun; Meng, Qingchun; Tian, Xue Feng; Zhu, Xiaole, Systems and methods for combining static and dynamic code analysis.
  67. McCorkendale, Bruce; Tian, Xue Feng; Gong, Sheng; Zhu, Xiaole; Mao, Jun; Meng, Qingchun; Huang, Ge Hua; Hu, Wei Guo Eric, Systems and methods for combining static and dynamic code analysis.
  68. Zakorzhevsky, Vyacheslav V.; Vinogradov, Dmitry V.; Pintiysky, Vladislav V.; Kirsanov, Dmitry A., Systems and methods for detecting malicious executable files containing an interpreter by combining emulators.
  69. Ferrie, Peter, Systems and methods for identifying external functions called by untrusted applications.
  70. Pereira, Shane, Systems and methods for scanning packed programs in response to detecting suspicious behaviors.
  71. Zakorzhevsky, Vyacheslav V.; Vinogradov, Dmitry V.; Pintiysky, Vladislav V.; Kirsanov, Dmitry A., Systems and methods for switching emulation of an executable file.
  72. Kirk, Terrance J.; Bialek, Matthew S.; Kospiah, Shaun; Lemm, Timothy M.; Thompson, Scott G., Systems and methods of analyzing a software component.
  73. Kirk, Terrance J.; Bialek, Matthew S.; Kospiah, Shaun; Lemm, Timothy M.; Thompson, Scott G., Systems and methods of analyzing a software component.
  74. Kirk, Terrance J.; Bialek, Matthew S.; Kospiah, Shaun; Lemm, Timothy M.; Thompson, Scott G., Systems and methods of analyzing a software component.
  75. Kospiah, Shaun S.; Grubel, Brian C.; Snare, Brett W., Systems and methods of analyzing a software component.
  76. Field, Scott A, Tagging obtained content for white and black listing.
  77. Amit, Yair; Guy, Lotem; Kalman, Daniel; Segal, Ori; Weisman, Omri, Targeted security testing.
  78. Amit, Yair; Guy, Lotem; Kalman, Daniel; Segal, Ori; Weisman, Omri, Targeted security testing.
  79. Hsu, Ming-Fa; Kuo, Chen-Yu; Mahadevan, Hariharan; Yu, Ying-Hung, Techniques for managing security modes applied to application program execution.
섹션별 컨텐츠 바로가기

AI-Helper ※ AI-Helper는 오픈소스 모델을 사용합니다.

AI-Helper 아이콘
AI-Helper
안녕하세요, AI-Helper입니다. 좌측 "선택된 텍스트"에서 텍스트를 선택하여 요약, 번역, 용어설명을 실행하세요.
※ AI-Helper는 부적절한 답변을 할 수 있습니다.

선택된 텍스트

맨위로