发明名称 SYSTEM AND METHOD FOR DETECTING NEW MALICIOUS EXECUTABLES, BASED ON DISCOVERING AND MONITORING CHARACTERISTIC SYSTEM CALL SEQUENCES
摘要 The invention relates to a method for detecting malicious executables, which comprises: (a) in an offline training phase, finding a collection of system call sequences that are characteristic only to malicious files, when such malicious files are executed, and storing said sequences in a database; and, in runtime, for each running executable, continuously monitoring its issued run-time system calls and comparing with the stored sequences of system calls within the database to determine whether there exists a match between a portion of the sequence of the run-time system calls and one or more of the database sequences, and when such a match is found, declaring said executable as malicious.
申请公布号 US2010229239(A1) 申请公布日期 2010.09.09
申请号 US20100697559 申请日期 2010.02.01
申请人 DEUTSCHE TELEKOM AG 发明人 ROZENBERG BORIS;GUDES EHUD;ELOVICI YUVAL
分类号 G06F11/30;G06F21/55 主分类号 G06F11/30
代理机构 代理人
主权项
地址