发明名称 THE METHOD AND APPARATUS FOR ANALYZING EXPLOIT CODE IN NON-EXECUTABLE FILE USING VIRTUAL ENVIRONMENT
摘要 A method and an apparatus for analyzing the malware software within a non-executable file which uses the virtual environment use the object program having the weak point in the virtual environment are provided to analyze the malware included in the non-executable file safely. A program execution part(114) outputs register value of an object program by loading non-executable file analyzed in an object program. A program run analysis part(122) analyzes the outputted register value. In case the register value indicates a domain except a normal code domain, the program run analysis part stores log information about the operation of the object program in the log information database(124). A malware analyze part(126) extracts and analyzes malware included in the non-executable file based on log information. When the outputted register value begins to indicate domain except the normal code area, the program run analysis part begins to store the log information.
申请公布号 KR20090034648(A) 申请公布日期 2009.04.08
申请号 KR20070100009 申请日期 2007.10.04
申请人 ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE 发明人 CHOI, YOUNG HAN;KIM, HYOUNG CHUN;LEE, DO HOON
分类号 G06F15/00 主分类号 G06F15/00
代理机构 代理人
主权项
地址