摘要 |
The present invention monitors a behavior of malware (program), and generates a log which associates identification information of an invoked library function, input data to the library function, output data from the library function and a taint tag for uniquely specifying output data every time the program invokes a library function. Further, the present invention refers to a taint tag set to output data from an information processing device and a log, tracks a dependent relationship between items of data input and output to and from libraries and specifies a library function which has generated the output data from the information processing device. |