发明名称 System and method for detecting new malicious executables, based on discovering and monitoring characteristic system call sequences
摘要 The invention relates to a method for detecting malicious executables, which comprises: in an offline training phase, finding a collection of system call sequences that are characteristic only to malicious files, when such malicious files are executed, and storing said sequences in a database; and, in runtime, for each running executable, continuously monitoring its issued run-time system calls and comparing with the stored sequences of system calls within the database to determine whether there exists a match between a portion of the sequence of the run-time system calls and one or more of the database sequences, and when such a match is found, declaring said executable as malicious.
申请公布号 US8332944(B2) 申请公布日期 2012.12.11
申请号 US20100697559 申请日期 2010.02.01
申请人 ROZENBERG BORIS;GUDES EHUD;ELOVICI YUVAL 发明人 ROZENBERG BORIS;GUDES EHUD;ELOVICI YUVAL
分类号 G06F12/14;G06F21/55 主分类号 G06F12/14
代理机构 代理人
主权项
地址