CN102819697A - 一种基于线程反编译的多平台恶意代码检测方法和系统 - Google Patents
一种基于线程反编译的多平台恶意代码检测方法和系统 Download PDFInfo
- Publication number
- CN102819697A CN102819697A CN2011104406330A CN201110440633A CN102819697A CN 102819697 A CN102819697 A CN 102819697A CN 2011104406330 A CN2011104406330 A CN 2011104406330A CN 201110440633 A CN201110440633 A CN 201110440633A CN 102819697 A CN102819697 A CN 102819697A
- Authority
- CN
- China
- Prior art keywords
- thread
- decompiling
- sequence
- malicious
- malicious code
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
- 238000000034 method Methods 0.000 title claims abstract description 32
- 238000000605 extraction Methods 0.000 claims abstract description 37
- 238000001514 detection method Methods 0.000 claims abstract description 25
- 230000003068 static effect Effects 0.000 claims description 10
- 239000000284 extract Substances 0.000 claims description 9
- 230000006870 function Effects 0.000 claims description 9
- 230000003542 behavioural effect Effects 0.000 claims description 5
- 238000007689 inspection Methods 0.000 claims description 3
- 230000013011 mating Effects 0.000 claims description 3
- 238000005516 engineering process Methods 0.000 description 4
- 239000008186 active pharmaceutical agent Substances 0.000 description 2
- 230000006399 behavior Effects 0.000 description 2
- 230000008901 benefit Effects 0.000 description 2
- 238000010586 diagram Methods 0.000 description 2
- 230000000694 effects Effects 0.000 description 2
- 241000700605 Viruses Species 0.000 description 1
- 230000000845 anti-microbial effect Effects 0.000 description 1
- 230000002155 anti-virotic effect Effects 0.000 description 1
- 239000004599 antimicrobial Substances 0.000 description 1
- 230000009286 beneficial effect Effects 0.000 description 1
- 238000006243 chemical reaction Methods 0.000 description 1
- 239000012467 final product Substances 0.000 description 1
- 230000035772 mutation Effects 0.000 description 1
Images
Landscapes
- Debugging And Monitoring (AREA)
Abstract
Description
Claims (12)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201110440633.0A CN102819697B (zh) | 2011-12-26 | 2011-12-26 | 一种基于线程反编译的多平台恶意代码检测方法和系统 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201110440633.0A CN102819697B (zh) | 2011-12-26 | 2011-12-26 | 一种基于线程反编译的多平台恶意代码检测方法和系统 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN102819697A true CN102819697A (zh) | 2012-12-12 |
CN102819697B CN102819697B (zh) | 2015-07-22 |
Family
ID=47303807
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201110440633.0A Active CN102819697B (zh) | 2011-12-26 | 2011-12-26 | 一种基于线程反编译的多平台恶意代码检测方法和系统 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN102819697B (zh) |
Cited By (15)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN103679024A (zh) * | 2013-11-19 | 2014-03-26 | 百度国际科技(深圳)有限公司 | 病毒的处理方法及设备 |
CN103761479A (zh) * | 2014-01-09 | 2014-04-30 | 北京奇虎科技有限公司 | 恶意程序的扫描方法和装置 |
CN103761475A (zh) * | 2013-12-30 | 2014-04-30 | 北京奇虎科技有限公司 | 检测智能终端中恶意代码的方法及装置 |
CN103905419A (zh) * | 2013-12-04 | 2014-07-02 | 哈尔滨安天科技股份有限公司 | 一种文件鉴定装置及方法 |
CN104091121A (zh) * | 2014-06-12 | 2014-10-08 | 上海交通大学 | 对Android重打包恶意软件的恶意代码的检测、切除和恢复的方法 |
CN104134039A (zh) * | 2014-07-24 | 2014-11-05 | 北京奇虎科技有限公司 | 病毒查杀方法、客户端、服务器以及病毒查杀系统 |
CN104657664A (zh) * | 2013-11-19 | 2015-05-27 | 百度在线网络技术(北京)有限公司 | 病毒的处理方法及设备 |
CN106909839A (zh) * | 2015-12-22 | 2017-06-30 | 北京奇虎科技有限公司 | 一种提取样本代码特征的方法及装置 |
CN107038375A (zh) * | 2017-03-22 | 2017-08-11 | 国家计算机网络与信息安全管理中心 | 一种获取被感染的宿主程序的解密方法及系统 |
CN107220544A (zh) * | 2016-03-22 | 2017-09-29 | 趣斯特派普有限公司 | 用于检测感兴趣指令序列的系统和方法 |
US9792433B2 (en) | 2013-12-30 | 2017-10-17 | Beijing Qihoo Technology Company Limited | Method and device for detecting malicious code in an intelligent terminal |
CN109635565A (zh) * | 2018-11-28 | 2019-04-16 | 江苏通付盾信息安全技术有限公司 | 恶意程序的检测方法、装置、计算设备及计算机存储介质 |
CN112395593A (zh) * | 2019-08-15 | 2021-02-23 | 奇安信安全技术(珠海)有限公司 | 指令执行序列的监测方法及装置、存储介质、计算机设备 |
CN115543586A (zh) * | 2022-11-28 | 2022-12-30 | 成都安易迅科技有限公司 | 应用层系统进程的启动方法、装置、设备及可读存储介质 |
TWI791418B (zh) * | 2015-12-08 | 2023-02-11 | 美商飛塔公司 | 用以檢測運作時期所產生碼中之惡意碼的系統及方法、與相關電腦程式產品 |
Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101154258A (zh) * | 2007-08-14 | 2008-04-02 | 电子科技大学 | 恶意程序动态行为自动化分析系统与方法 |
CN101989322A (zh) * | 2010-11-19 | 2011-03-23 | 北京安天电子设备有限公司 | 自动提取恶意代码内存特征的方法和系统 |
US20110271343A1 (en) * | 2010-04-28 | 2011-11-03 | Electronics And Telecommunications Research Institute | Apparatus, system and method for detecting malicious code |
-
2011
- 2011-12-26 CN CN201110440633.0A patent/CN102819697B/zh active Active
Patent Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101154258A (zh) * | 2007-08-14 | 2008-04-02 | 电子科技大学 | 恶意程序动态行为自动化分析系统与方法 |
US20110271343A1 (en) * | 2010-04-28 | 2011-11-03 | Electronics And Telecommunications Research Institute | Apparatus, system and method for detecting malicious code |
CN101989322A (zh) * | 2010-11-19 | 2011-03-23 | 北京安天电子设备有限公司 | 自动提取恶意代码内存特征的方法和系统 |
Cited By (21)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN103679024A (zh) * | 2013-11-19 | 2014-03-26 | 百度国际科技(深圳)有限公司 | 病毒的处理方法及设备 |
CN103679024B (zh) * | 2013-11-19 | 2015-03-25 | 百度在线网络技术(北京)有限公司 | 病毒的处理方法及设备 |
CN104657664A (zh) * | 2013-11-19 | 2015-05-27 | 百度在线网络技术(北京)有限公司 | 病毒的处理方法及设备 |
CN104657664B (zh) * | 2013-11-19 | 2018-02-02 | 百度在线网络技术(北京)有限公司 | 病毒的处理方法及设备 |
CN103905419A (zh) * | 2013-12-04 | 2014-07-02 | 哈尔滨安天科技股份有限公司 | 一种文件鉴定装置及方法 |
US9792433B2 (en) | 2013-12-30 | 2017-10-17 | Beijing Qihoo Technology Company Limited | Method and device for detecting malicious code in an intelligent terminal |
CN103761475A (zh) * | 2013-12-30 | 2014-04-30 | 北京奇虎科技有限公司 | 检测智能终端中恶意代码的方法及装置 |
CN103761475B (zh) * | 2013-12-30 | 2017-04-26 | 北京奇虎科技有限公司 | 检测智能终端中恶意代码的方法及装置 |
CN103761479A (zh) * | 2014-01-09 | 2014-04-30 | 北京奇虎科技有限公司 | 恶意程序的扫描方法和装置 |
CN104091121A (zh) * | 2014-06-12 | 2014-10-08 | 上海交通大学 | 对Android重打包恶意软件的恶意代码的检测、切除和恢复的方法 |
CN104091121B (zh) * | 2014-06-12 | 2017-07-18 | 上海交通大学 | 对Android重打包恶意软件的恶意代码的检测、切除和恢复的方法 |
CN104134039A (zh) * | 2014-07-24 | 2014-11-05 | 北京奇虎科技有限公司 | 病毒查杀方法、客户端、服务器以及病毒查杀系统 |
TWI791418B (zh) * | 2015-12-08 | 2023-02-11 | 美商飛塔公司 | 用以檢測運作時期所產生碼中之惡意碼的系統及方法、與相關電腦程式產品 |
CN106909839A (zh) * | 2015-12-22 | 2017-06-30 | 北京奇虎科技有限公司 | 一种提取样本代码特征的方法及装置 |
CN106909839B (zh) * | 2015-12-22 | 2020-04-17 | 北京奇虎科技有限公司 | 一种提取样本代码特征的方法及装置 |
CN107220544A (zh) * | 2016-03-22 | 2017-09-29 | 趣斯特派普有限公司 | 用于检测感兴趣指令序列的系统和方法 |
CN107038375A (zh) * | 2017-03-22 | 2017-08-11 | 国家计算机网络与信息安全管理中心 | 一种获取被感染的宿主程序的解密方法及系统 |
CN109635565A (zh) * | 2018-11-28 | 2019-04-16 | 江苏通付盾信息安全技术有限公司 | 恶意程序的检测方法、装置、计算设备及计算机存储介质 |
CN112395593A (zh) * | 2019-08-15 | 2021-02-23 | 奇安信安全技术(珠海)有限公司 | 指令执行序列的监测方法及装置、存储介质、计算机设备 |
CN112395593B (zh) * | 2019-08-15 | 2024-03-29 | 奇安信安全技术(珠海)有限公司 | 指令执行序列的监测方法及装置、存储介质、计算机设备 |
CN115543586A (zh) * | 2022-11-28 | 2022-12-30 | 成都安易迅科技有限公司 | 应用层系统进程的启动方法、装置、设备及可读存储介质 |
Also Published As
Publication number | Publication date |
---|---|
CN102819697B (zh) | 2015-07-22 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN102819697A (zh) | 一种基于线程反编译的多平台恶意代码检测方法和系统 | |
US9824212B2 (en) | Method and system for recognizing advertisement plug-ins | |
CN106951780B (zh) | 重打包恶意应用的静态检测方法和装置 | |
US9262296B1 (en) | Static feature extraction from structured files | |
US10165001B2 (en) | Method and device for processing computer viruses | |
CN103607413B (zh) | 一种网站后门程序检测的方法及装置 | |
CN103365699B (zh) | 基于apk的系统api和运行时字符串的提取方法及系统 | |
WO2015101097A1 (zh) | 特征提取的方法及装置 | |
CN101441687B (zh) | 一种提取病毒文件的病毒特征的方法及其装置 | |
US10445501B2 (en) | Detecting malicious scripts | |
CN108734012A (zh) | 恶意软件识别方法、装置及电子设备 | |
KR101582601B1 (ko) | 액티비티 문자열 분석에 의한 안드로이드 악성코드 검출 방법 | |
CN103927484A (zh) | 基于Qemu模拟器的恶意程序行为捕获方法 | |
CN112041815A (zh) | 恶意软件检测 | |
CN102004879B (zh) | 一种识别可信任进程的方法 | |
CN102819723A (zh) | 一种恶意二维码检测方法和系统 | |
CN103617393A (zh) | 一种基于支持向量机的移动互联网恶意应用软件检测方法 | |
CN102592080A (zh) | flash恶意文件检测方法及装置 | |
Immanuel et al. | Android cache taxonomy and forensic process | |
CN103810428A (zh) | 一种宏病毒检测方法及装置 | |
KR101816045B1 (ko) | 악성코드 룰셋을 이용한 악성코드 탐지 시스템 및 방법 | |
CN104217162A (zh) | 一种智能终端恶意软件的检测方法及系统 | |
CN105550581A (zh) | 一种恶意代码检测方法及装置 | |
CN103294953A (zh) | 一种手机恶意代码检测方法及系统 | |
CN105718795A (zh) | Linux下基于特征码的恶意代码取证方法及系统 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
C14 | Grant of patent or utility model | ||
GR01 | Patent grant | ||
PE01 | Entry into force of the registration of the contract for pledge of patent right | ||
PE01 | Entry into force of the registration of the contract for pledge of patent right |
Denomination of invention: Method and system for detecting multi-platform malicious codes based on thread decompiling Effective date of registration: 20170621 Granted publication date: 20150722 Pledgee: Bank of Longjiang, Limited by Share Ltd, Harbin Limin branch Pledgor: Harbin Antiy Technology Co., Ltd. Registration number: 2017110000004 |
|
PC01 | Cancellation of the registration of the contract for pledge of patent right |
Date of cancellation: 20190614 Granted publication date: 20150722 Pledgee: Bank of Longjiang, Limited by Share Ltd, Harbin Limin branch Pledgor: Harbin Antiy Technology Co., Ltd. Registration number: 2017110000004 |
|
PC01 | Cancellation of the registration of the contract for pledge of patent right | ||
CP03 | Change of name, title or address | ||
CP03 | Change of name, title or address |
Address after: 150028 Building 7, Innovation Plaza, Science and Technology Innovation City, Harbin Hi-tech Industrial Development Zone, Heilongjiang Province (838 Shikun Road) Patentee after: Harbin antiy Technology Group Limited by Share Ltd Address before: 150090 room 506, Hongqi Street, Nangang District, Harbin Development Zone, Heilongjiang, China, 162 Patentee before: Harbin Antiy Technology Co., Ltd. |
|
PE01 | Entry into force of the registration of the contract for pledge of patent right | ||
PE01 | Entry into force of the registration of the contract for pledge of patent right |
Denomination of invention: Method and system for detecting multi-platform malicious codes based on thread decompiling Effective date of registration: 20190828 Granted publication date: 20150722 Pledgee: Bank of Longjiang, Limited by Share Ltd, Harbin Limin branch Pledgor: Harbin antiy Technology Group Limited by Share Ltd Registration number: Y2019230000002 |
|
CP01 | Change in the name or title of a patent holder | ||
CP01 | Change in the name or title of a patent holder |
Address after: 150028 building 7, innovation and entrepreneurship square, science and technology innovation city, Harbin high tech Industrial Development Zone, Heilongjiang Province (No. 838, Shikun Road) Patentee after: Antan Technology Group Co.,Ltd. Address before: 150028 building 7, innovation and entrepreneurship square, science and technology innovation city, Harbin high tech Industrial Development Zone, Heilongjiang Province (No. 838, Shikun Road) Patentee before: Harbin Antian Science and Technology Group Co.,Ltd. |
|
PC01 | Cancellation of the registration of the contract for pledge of patent right | ||
PC01 | Cancellation of the registration of the contract for pledge of patent right |
Date of cancellation: 20211119 Granted publication date: 20150722 Pledgee: Bank of Longjiang Limited by Share Ltd. Harbin Limin branch Pledgor: Harbin Antian Science and Technology Group Co.,Ltd. Registration number: Y2019230000002 |