发明名称 DETECTING EXPLOIT CODE IN NETWORK FLOWS
摘要 The present invention discloses detecting exploit code in network flows. The network data packets are intercepted by a flow monitor, which generates data flows from the intercepted data packets. A content filter is utilized for filtering out legitimate programs from the data flows, and the unfiltered portions are provided to an executable code recognizer which detects executable code. The executable code recognizer also performs convergent binary disassembly on the unfiltered portions of the data flows, constructs a control flow graph, control flow analysis, data flow analysis, and constraint enforcement in order to detect executable code.
申请公布号 WO2007001439(A3) 申请公布日期 2007.12.21
申请号 WO2005US39437 申请日期 2005.10.28
申请人 TELCORDIA TECHNOLOGIES, INC.;VAN DEN BERG, ERIC;CHINCHANI, RAMKUMAR 发明人 VAN DEN BERG, ERIC;CHINCHANI, RAMKUMAR
分类号 G06F17/00 主分类号 G06F17/00
代理机构 代理人
主权项
地址
您可能感兴趣的专利