发明名称 SYSTEM AND METHOD FOR TRACKING REMOTE ACCESS SERVER OF MALICIOUS CODE
摘要 The present invention relates to a system and method for tracking a remote server accessed by a code-injection of malicious code. A system for tracking a remote access server of a malicious code comprises: an image load monitoring part for monitoring whether a process loaded in a memory is included in a communication module; a monitoring module insertion part for inserting a monitoring module, which monitors an operation for the communication module into the process; a network connection management part for receiving communication information between the communication module and the remote access server from the monitoring module inserted into the process and managing the received information; a malicious code diagnosis part for diagnosing malice of the process; and an access server tracking part for asking a query to the network connection management part about the process diagnosed as malicious by the malicious code diagnosis part and obtaining information on a remote access server having communicated with the process diagnosed as malicious.
申请公布号 KR101410289(B1) 申请公布日期 2014.06.20
申请号 KR20130012789 申请日期 2013.02.05
申请人 INCA INTERNET CO., LTD. 发明人 KO, BO SEUNG;KIM, DAE HEE
分类号 H04L12/26;G06F21/50 主分类号 H04L12/26
代理机构 代理人
主权项
地址