发明名称 METHOD OF PENALTY-BASED UNKNOWN MALWARE DETECTION AND RESPONSE
摘要 The present invention relates to a system for detecting and coping with unknown malware based on a penalty and a method thereof and, more specifically, to a system and method for constructing a penalty scoring scheme based on static and dynamic characteristics of existing malwares, continuously monitoring processes executed on a computer system to give a penalty according to penalty criteria, determining that a malware occurs when the penalty more than a reference value is generated, and performs a countermeasure according to a set command, in order to detect and cope with the unknown malware of which signature is not obtained as well as the known malware. The present invention adopts a scheme of continuously observing the processes at a user terminal, which is different from a conventional scheme of performing an analysis behavior for a set time, and then determining whether the malware occurs, so can effectively detect the latest advanced persistent threat (APT) attack scheme of performing a malicious behavior little by little over several months to make an intrusion into the computer system.
申请公布号 KR101580624(B1) 申请公布日期 2015.12.28
申请号 KR20140159790 申请日期 2014.11.17
申请人 AGENCY FOR DEFENSE DEVELOPMENT 发明人 YOO, CHAN GON;YUN, HO SANG;PARK, JEONG CHAN
分类号 H04L12/26;H04L12/22 主分类号 H04L12/26
代理机构 代理人
主权项
地址