发明名称 DETECTION OF MALICIOUS SCRIPTING LANGUAGE CODE IN A NETWORK ENVIRONMENT
摘要 A method is provided in one example embodiment and includes initiating an execution of a compiled script, evaluating a function called in the compiled script, detecting an execution event based on at least a first criterion, and storing information associated with the execution event in an execution event queue. The method also includes verifying a correlation signature based on information associated with at least one execution event in the execution event queue. In specific embodiments, the method includes evaluating an assignment statement of a script during compilation of the script by a compiler, detecting a compilation event based on at least a second criterion, and storing information associated with the compilation event in a compilation event queue. In yet additional embodiments, the verification of the correlation signature is based in part on information associated with one or more compilation events in the compilation event queue.
申请公布号 WO2014113597(A1) 申请公布日期 2014.07.24
申请号 WO2014US11907 申请日期 2014.01.16
申请人 MCAFEE INC.;XU, CHONG;SUN, BING;SINGH, NAVTEJ;LIN, YICHONG;BU, ZHENG 发明人 XU, CHONG;SUN, BING;SINGH, NAVTEJ;LIN, YICHONG;BU, ZHENG
分类号 G06F21/50;G06F21/56 主分类号 G06F21/50
代理机构 代理人
主权项
地址