发明名称 METHOD AND APPARATUS FOR MALWARE DETECTION
摘要 An approach is provided for providing an offline malware detection, and in addition a real-time malware detection. The offline malware detection may comprise: detecting at least one of function calling map of the application offline, wherein a function calling map records relationships of callings among functions called by the application; extracting patterns of the function callings of the application from the at least one function calling map; and comparing the extracted pattern with at least one basic pattern of normal applications. The real-time malware detection may comprises: running an application in a real environment; recording behaviors of the application at runtime of the application; extracting behavior patterns from the recorded behaviors; and comparing the extracted behavior patterns with at least one of basic patterns of normal applications or patterns previously recorded for the application.
申请公布号 EP3090375(A1) 申请公布日期 2016.11.09
申请号 EP20130900779 申请日期 2013.12.30
申请人 NOKIA TECHNOLOGIES OY 发明人 YAN, ZHENG
分类号 G06F21/56 主分类号 G06F21/56
代理机构 代理人
主权项
地址