发明名称 Method for detecting new malicious executables, based on discovering and monitoring characteristic system call sequences
摘要 <p>The invention relates to a method for detecting malicious executables, which comprises: (a) in an offline training phase, finding a collection of system call sequences that are characteristic only to malicious files, when such malicious files are executed, and storing said sequences in a database; and, in runtime, for each running executable, continuously monitoring its issued run-time system calls and comparing with the stored sequences of system calls within the database to determine whether there exists a match between a portion of the sequence of the run-time system calls and one or more of the database sequences, and when such a match is found, declaring said executable as malicious.</p>
申请公布号 EP2228743(A1) 申请公布日期 2010.09.15
申请号 EP20100001352 申请日期 2010.02.10
申请人 DEUTSCHE TELEKOM AG 发明人 ROZENBERG, BORIS;GUDES, EHUD;ELOVICI, YUVAL
分类号 G06F21/55 主分类号 G06F21/55
代理机构 代理人
主权项
地址