发明名称 Obfuscated malware detection
摘要 Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for detecting obfuscated malware. In one aspect, a method includes identifying call instructions in a binary executable; executing the call instruction; executing instructions subsequent to a target of the call instruction; determining that an address identified by a stack pointer is different from the return address; in response to the determination that the address is different, determining if there is a non-obfuscation signal; if there is a non-obfuscation signal, identifying the call instruction as a non-obfuscated call instruction; if there is not a non-obfuscation signal, identifying the call instruction as a possibly obfuscated call instruction; determining whether the call instructions identified as possibly obfuscated call instructions exceeds a threshold; in response to the determination that the call instructions identified as possibly obfuscated call instructions exceeds the threshold, identifying the executable as an obfuscated executable.
申请公布号 US8499352(B2) 申请公布日期 2013.07.30
申请号 US201213440595 申请日期 2012.04.05
申请人 MATHUR RACHIT;COCHIN CEDRIC;MCAFEE, INC. 发明人 MATHUR RACHIT;COCHIN CEDRIC
分类号 G06F11/28;G06F11/30;G06F12/14;G08B23/00 主分类号 G06F11/28
代理机构 代理人
主权项
地址