发明名称 Method and apparatus for detecting malicious shell codes using debugging events
摘要 An apparatus for detecting malicious shell codes using a debugging event includes an alert setting unit configured to set a mother program to run a non-executable file to trigger the debugging event when a mother process created by the mother program tries to execute a code with no execution attribute; and an information storage unit configured to store information on an address range in which modules to be used by the mother process are loaded in a memory. Further, the apparatus includes a malicious code determination unit configured to determine whether the non-executable file is malicious using the information on the address range when there occurs the debugging event.
申请公布号 US8646076(B1) 申请公布日期 2014.02.04
申请号 US201313875421 申请日期 2013.05.02
申请人 AHNLAB, INC. 发明人 LIM CHA SUNG;LEE JU SEOK
分类号 G06F12/14 主分类号 G06F12/14
代理机构 代理人
主权项
地址
您可能感兴趣的专利