发明名称 PROBABILISTIC SHELLCODE DETECTION
摘要 Various embodiments include a method of detecting shell code in an arbitrary file comprising determining where one or more candidate areas exist within an arbitrary file, searching at least one nearby area surrounding each of the one or more candidate areas within the arbitrary file for an instruction candidate, and calculating for any such instruction candidate a statistical probability based on a disassembly of instructions starting at a found offset for the instruction candidate that the disassembled instructions are shellcode.
申请公布号 US2010031359(A1) 申请公布日期 2010.02.04
申请号 US20080103498 申请日期 2008.04.15
申请人 SECURE COMPUTING CORPORATION 发明人 ALME CHRISTOPH
分类号 G06F21/22;G06N5/02 主分类号 G06F21/22
代理机构 代理人
主权项
地址