CN103559447A - 一种基于病毒样本特征的检测方法、检测装置及检测系统 - Google Patents
一种基于病毒样本特征的检测方法、检测装置及检测系统 Download PDFInfo
- Publication number
- CN103559447A CN103559447A CN201310573299.5A CN201310573299A CN103559447A CN 103559447 A CN103559447 A CN 103559447A CN 201310573299 A CN201310573299 A CN 201310573299A CN 103559447 A CN103559447 A CN 103559447A
- Authority
- CN
- China
- Prior art keywords
- script
- statement
- unit
- virtual
- word
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
- 241000700605 Viruses Species 0.000 title claims abstract description 269
- 238000001514 detection method Methods 0.000 title claims abstract description 162
- 238000013515 script Methods 0.000 claims abstract description 438
- 238000004458 analytical method Methods 0.000 claims abstract description 83
- 230000014509 gene expression Effects 0.000 claims description 211
- 230000002155 anti-virotic effect Effects 0.000 claims description 51
- 230000008878 coupling Effects 0.000 claims 1
- 238000010168 coupling process Methods 0.000 claims 1
- 238000005859 coupling reaction Methods 0.000 claims 1
- 238000000034 method Methods 0.000 abstract description 21
- 230000006870 function Effects 0.000 description 24
- 230000003542 behavioural effect Effects 0.000 description 15
- 238000010195 expression analysis Methods 0.000 description 13
- 238000010586 diagram Methods 0.000 description 6
- 230000000694 effects Effects 0.000 description 6
- 230000008569 process Effects 0.000 description 6
- 238000007689 inspection Methods 0.000 description 4
- 230000008901 benefit Effects 0.000 description 3
- 230000015572 biosynthetic process Effects 0.000 description 2
- 238000004364 calculation method Methods 0.000 description 2
- 238000004590 computer program Methods 0.000 description 2
- 238000013473 artificial intelligence Methods 0.000 description 1
- 238000000429 assembly Methods 0.000 description 1
- 230000009286 beneficial effect Effects 0.000 description 1
- 238000004422 calculation algorithm Methods 0.000 description 1
- 238000004891 communication Methods 0.000 description 1
- 230000001066 destructive effect Effects 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 208000015181 infectious disease Diseases 0.000 description 1
- 230000007246 mechanism Effects 0.000 description 1
- 238000011084 recovery Methods 0.000 description 1
- 230000008685 targeting Effects 0.000 description 1
- 230000000007 visual effect Effects 0.000 description 1
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/562—Static detection
- G06F21/563—Static detection by source code analysis
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Virology (AREA)
- Health & Medical Sciences (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- General Health & Medical Sciences (AREA)
- Devices For Executing Special Programs (AREA)
- Stored Programmes (AREA)
Abstract
Description
Claims (10)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201310573299.5A CN103559447B (zh) | 2013-11-15 | 2013-11-15 | 一种基于病毒样本特征的检测方法、检测装置及检测系统 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201310573299.5A CN103559447B (zh) | 2013-11-15 | 2013-11-15 | 一种基于病毒样本特征的检测方法、检测装置及检测系统 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN103559447A true CN103559447A (zh) | 2014-02-05 |
CN103559447B CN103559447B (zh) | 2016-05-25 |
Family
ID=50013693
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201310573299.5A Active CN103559447B (zh) | 2013-11-15 | 2013-11-15 | 一种基于病毒样本特征的检测方法、检测装置及检测系统 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN103559447B (zh) |
Cited By (7)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN104331663A (zh) * | 2014-10-31 | 2015-02-04 | 北京奇虎科技有限公司 | web shell的检测方法以及web服务器 |
CN104408368A (zh) * | 2014-11-21 | 2015-03-11 | 中国联合网络通信集团有限公司 | 网址检测方法与装置 |
CN106020913A (zh) * | 2016-06-06 | 2016-10-12 | 北京邮电大学 | 一种缺陷检测工具更新方法及装置 |
CN106845221A (zh) * | 2016-11-09 | 2017-06-13 | 哈尔滨安天科技股份有限公司 | 一种基于语法形式的脚本类文件格式识别方法和系统 |
CN106909843A (zh) * | 2015-12-22 | 2017-06-30 | 北京奇虎科技有限公司 | 一种计算机病毒的检测方法及装置 |
CN110580408A (zh) * | 2019-09-19 | 2019-12-17 | 北京天融信网络安全技术有限公司 | 一种数据处理方法及电子设备 |
CN112307478A (zh) * | 2020-11-30 | 2021-02-02 | 深信服科技股份有限公司 | 一种脚本病毒检测方法、系统及电子设备和存储介质 |
Families Citing this family (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN106909842B (zh) * | 2015-12-22 | 2021-01-29 | 北京奇虎科技有限公司 | 一种数据恢复方法及装置 |
Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20020073330A1 (en) * | 2000-07-14 | 2002-06-13 | Computer Associates Think, Inc. | Detection of polymorphic script language viruses by data driven lexical analysis |
CN1983295A (zh) * | 2005-12-12 | 2007-06-20 | 北京瑞星国际软件有限公司 | 病毒识别方法及装置 |
CN101599947A (zh) * | 2008-06-06 | 2009-12-09 | 盛大计算机(上海)有限公司 | 基于web网页的木马病毒扫描方法 |
CN102043919A (zh) * | 2010-12-27 | 2011-05-04 | 北京安天电子设备有限公司 | 基于脚本虚拟机的漏洞通用检测方法和系统 |
CN102693396A (zh) * | 2012-06-11 | 2012-09-26 | 中南大学 | 一种基于虚拟执行模式的Flash漏洞检测方法 |
-
2013
- 2013-11-15 CN CN201310573299.5A patent/CN103559447B/zh active Active
Patent Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20020073330A1 (en) * | 2000-07-14 | 2002-06-13 | Computer Associates Think, Inc. | Detection of polymorphic script language viruses by data driven lexical analysis |
CN1983295A (zh) * | 2005-12-12 | 2007-06-20 | 北京瑞星国际软件有限公司 | 病毒识别方法及装置 |
CN101599947A (zh) * | 2008-06-06 | 2009-12-09 | 盛大计算机(上海)有限公司 | 基于web网页的木马病毒扫描方法 |
CN102043919A (zh) * | 2010-12-27 | 2011-05-04 | 北京安天电子设备有限公司 | 基于脚本虚拟机的漏洞通用检测方法和系统 |
CN102693396A (zh) * | 2012-06-11 | 2012-09-26 | 中南大学 | 一种基于虚拟执行模式的Flash漏洞检测方法 |
Cited By (11)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN104331663A (zh) * | 2014-10-31 | 2015-02-04 | 北京奇虎科技有限公司 | web shell的检测方法以及web服务器 |
CN104331663B (zh) * | 2014-10-31 | 2017-09-01 | 北京奇虎科技有限公司 | web shell的检测方法以及web服务器 |
CN104408368A (zh) * | 2014-11-21 | 2015-03-11 | 中国联合网络通信集团有限公司 | 网址检测方法与装置 |
CN104408368B (zh) * | 2014-11-21 | 2017-07-21 | 中国联合网络通信集团有限公司 | 网址检测方法与装置 |
CN106909843A (zh) * | 2015-12-22 | 2017-06-30 | 北京奇虎科技有限公司 | 一种计算机病毒的检测方法及装置 |
CN106020913A (zh) * | 2016-06-06 | 2016-10-12 | 北京邮电大学 | 一种缺陷检测工具更新方法及装置 |
CN106020913B (zh) * | 2016-06-06 | 2019-06-14 | 北京邮电大学 | 一种缺陷检测工具更新方法及装置 |
CN106845221A (zh) * | 2016-11-09 | 2017-06-13 | 哈尔滨安天科技股份有限公司 | 一种基于语法形式的脚本类文件格式识别方法和系统 |
CN110580408A (zh) * | 2019-09-19 | 2019-12-17 | 北京天融信网络安全技术有限公司 | 一种数据处理方法及电子设备 |
CN110580408B (zh) * | 2019-09-19 | 2022-03-11 | 北京天融信网络安全技术有限公司 | 一种数据处理方法及电子设备 |
CN112307478A (zh) * | 2020-11-30 | 2021-02-02 | 深信服科技股份有限公司 | 一种脚本病毒检测方法、系统及电子设备和存储介质 |
Also Published As
Publication number | Publication date |
---|---|
CN103559447B (zh) | 2016-05-25 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN103559447B (zh) | 一种基于病毒样本特征的检测方法、检测装置及检测系统 | |
CN110826064B (zh) | 一种恶意文件的处理方法、装置、电子设备以及存储介质 | |
CN103632096B (zh) | 一种对设备进行安全检测的方法和装置 | |
US11086987B2 (en) | Malware detection in event loops | |
Zhou et al. | Fast, scalable detection of" piggybacked" mobile applications | |
CN103473506B (zh) | 用于识别恶意apk文件的方法和装置 | |
US10621349B2 (en) | Detection of malware using feature hashing | |
CN103679031B (zh) | 一种文件病毒免疫的方法和装置 | |
Feng et al. | Mobidroid: A performance-sensitive malware detection system on mobile platform | |
US9135443B2 (en) | Identifying malicious threads | |
CN103473501B (zh) | 一种基于云安全的恶意软件追踪方法 | |
Fass et al. | Doublex: Statically detecting vulnerable data flows in browser extensions at scale | |
CN103761478B (zh) | 恶意文件的判断方法及设备 | |
US8914889B2 (en) | False alarm detection for malware scanning | |
US11522885B1 (en) | System and method for information gain for malware detection | |
CN102882875B (zh) | 主动防御方法及装置 | |
CN104134039B (zh) | 病毒查杀方法、客户端、服务器以及病毒查杀系统 | |
CN103761476A (zh) | 特征提取的方法及装置 | |
CN104462971B (zh) | 根据应用程序声明特征识别恶意应用程序的方法和装置 | |
CN105631312B (zh) | 恶意程序的处理方法及系统 | |
WO2017012241A1 (zh) | 文件的检测方法、装置、设备及非易失性计算机存储介质 | |
US10127382B2 (en) | Malware detection method | |
CN104331663B (zh) | web shell的检测方法以及web服务器 | |
Apvrille et al. | Identifying unknown android malware with feature extractions and classification techniques | |
CN103279707A (zh) | 一种用于主动防御恶意程序的方法、设备及系统 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
C14 | Grant of patent or utility model | ||
GR01 | Patent grant | ||
CP01 | Change in the name or title of a patent holder |
Address after: 100088 room 112, block D, 28 new street, new street, Xicheng District, Beijing (Desheng Park) Patentee after: BEIJING QIHOO TECHNOLOGY Co.,Ltd. Patentee after: Beijing Qizhi Business Consulting Co.,Ltd. Address before: 100088 room 112, block D, 28 new street, new street, Xicheng District, Beijing (Desheng Park) Patentee before: BEIJING QIHOO TECHNOLOGY Co.,Ltd. Patentee before: Qizhi software (Beijing) Co.,Ltd. |
|
CP01 | Change in the name or title of a patent holder | ||
TR01 | Transfer of patent right |
Effective date of registration: 20210628 Address after: 100016 1773, 15 / F, 17 / F, building 3, No.10, Jiuxianqiao Road, Chaoyang District, Beijing Patentee after: Beijing Hongteng Intelligent Technology Co.,Ltd. Address before: 100088 room 112, block D, 28 new street, new street, Xicheng District, Beijing (Desheng Park) Patentee before: BEIJING QIHOO TECHNOLOGY Co.,Ltd. Patentee before: Beijing Qizhi Business Consulting Co.,Ltd. |
|
TR01 | Transfer of patent right | ||
CP01 | Change in the name or title of a patent holder |
Address after: 100016 1773, 15 / F, 17 / F, building 3, No.10, Jiuxianqiao Road, Chaoyang District, Beijing Patentee after: Sanliu0 Digital Security Technology Group Co.,Ltd. Address before: 100016 1773, 15 / F, 17 / F, building 3, No.10, Jiuxianqiao Road, Chaoyang District, Beijing Patentee before: Beijing Hongteng Intelligent Technology Co.,Ltd. |
|
CP01 | Change in the name or title of a patent holder |