发明名称 DETECTING SYSTEM FOR MALICIOUS BEHAVIOR BASED ON KERNEL MODE AND METHOD THEREOF
摘要 A system for detecting a malicious behavior of a kernel mode and a method thereof are provided to change the address of a dispatcher function, corresponding to the driving of an actual kernel mode driver, into an address value, corresponding to the virtual execution. A kernel mode object control module(200) grasps the address of a dispatcher function on a memory, which is calculated according to the actual driving of an arbitrary kernel mode driver based on object information about the kernel mode driver. In case the grasped actual address information of the dispatcher function is different from the address information returned from a kernel mode virtual execution module(100), the kernel mode object control module changes the address of the dispatcher function into the returned address.
申请公布号 KR20090088198(A) 申请公布日期 2009.08.19
申请号 KR20080013596 申请日期 2008.02.14
申请人 AHNLAB, INC. 发明人 KO, HANG HOON
分类号 G06F21/56;G06F21/50 主分类号 G06F21/56
代理机构 代理人
主权项
地址
您可能感兴趣的专利