发明名称 OBFUSCATED MALWARE DETECTION
摘要 Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for obfuscated malware. In one aspect, a method includes executing from a binary executable a call instruction and a plurality of instruction subsequent to a target of the call instruction, determining if the value identified by the stack pointer of the call stack is equal to a default value stored in the call stack prior to emulation, determining if there is a non-obfuscation signal resulting from the execution of the call instructions and the plurality of instructions, and if the value identified by the stack pointer is the default value and there is no obfuscation signal, identifying the call instruction as a possibly obfuscated call instruction. Additionally, the method includes determining that if the number of call instructions identified as possibly obfuscated call instructions exceeds a threshold number, identifying the binary executable as an obfuscated executable.
申请公布号 US2011145921(A1) 申请公布日期 2011.06.16
申请号 US20090639465 申请日期 2009.12.16
申请人 MCAFEE, INC. 发明人 MATHUR RACHIT;COCHIN CEDRIC
分类号 G06F11/00;G06F21/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址