发明名称 System and Method for Detection of Omnientrant Code Segments to Identify Potential Malicious Code
摘要 Methods, systems and media are shown for detecting omnientrant code segments to identify potential malicious code involving, for each offset of a code segment, disassembling the code segment from the offset, determining whether the disassembled code is executable, and incrementing an offset execution value. This approach also involves checking whether the offset execution value exceeds an alert threshold value and generating a malicious code alert for the code segment if the offset execution value exceeds the alert threshold value. Some examples further involve, for each executable offset, identifying a final execution address of the offset, comparing the final execution addresses of the offsets for the code segment, and generating the malicious code alert for the code segment if a proportion of the executable offsets have a common value for the final execution address exceeds a frequency threshold.
申请公布号 US2016328560(A1) 申请公布日期 2016.11.10
申请号 US201615147801 申请日期 2016.05.05
申请人 Leviathan, Inc. 发明人 Momot Falcon
分类号 G06F21/56;G06N7/00;G06F9/30 主分类号 G06F21/56
代理机构 代理人
主权项 1. A method for detecting omnientrant code segments to identify potential malicious code, the method comprising the steps of: for each offset of a code segment: disassembling the code segment from the offset,determining whether the disassembled code is executable, andincrementing an offset execution value; checking whether the offset execution value exceeds an alert threshold value; and generating a malicious code alert for the code segment if the offset execution value exceeds the alert threshold value.
地址 Seattle WA US