发明名称 GENERIC UNPACKING OF APPLICATIONS FOR MALWARE DETECTION
摘要 A technique for detecting malware in an executable allows unpacking of a packed executable before determining whether the executable is malware. In systems with hardware assisted virtualization, hardware virtualization features may be used to iteratively unpack a packed executable in a controlled manner without needing knowledge of a packing technique. Once the executable is completely unpacked, malware detection techniques, such as signature scanning, may be employed to determine whether the executable contains malware. Hardware assisted virtualization may be used to facilitate the scanning of the run-time executable in memory.
申请公布号 WO2014149627(A1) 申请公布日期 2014.09.25
申请号 WO2014US19960 申请日期 2014.03.03
申请人 MCAFEE, INC. 发明人 GUPTA, DEEPAK
分类号 G06F21/56 主分类号 G06F21/56
代理机构 代理人
主权项
地址