发明名称 METHOD AND SYSTEM FOR AUTOMATIC DETECTION AND ANALYSIS OF MALWARE
摘要 A method of detecting malicious software (malware) includes receiving a file and storing a memory baseline for a system. The method also includes copying the file to the system, executing the file on the system, terminating operation of the system, and storing a post-execution memory map. The method further includes analyzing the memory baseline and the post-execution memory map and determining that the file includes malware.
申请公布号 US2016156658(A1) 申请公布日期 2016.06.02
申请号 US201615003273 申请日期 2016.01.21
申请人 Verisign, Inc. 发明人 Thomas Ralph;Ligh Bruce Michael
分类号 H04L29/06;G06F9/44;G06F3/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method of detecting malicious software, the method comprising: storing, by an analysis system, a memory baseline for a first system, the memory baseline including information stored in volatile memory of the first system and non-volatile memory of the first system; executing, by the analysis system, a file on the first system using an operating system of the first system after the storing the memory baseline; storing, by the analysis system, a post-execution memory map of the first system, the post-execution memory map including information stored in the volatile memory of the first system and the non-volatile memory of the first system after the executing the file; analyzing, by the analysis system, the memory baseline and the post-execution memory map, wherein analyzing comprises: determining the presence of one or more processes that changed from the memory baseline to the post-execution memory map,determining timestamps associated with the one or more processes, andidentifying behaviors that indicate attempts to conceal a rootkit during the operation of the operating system; determining, by the analysis system, that the file comprises malicious software based on the analyzing; determining, by the analysis system, a timeline of activities performed by the malicious software based on the timestamps; and reporting, by the analysis system, the malicious software including a list of the one or more processes that changed and the timeline.
地址 Reston VA US