CN106127052A - 恶意程序的识别方法及装置 - Google Patents
恶意程序的识别方法及装置 Download PDFInfo
- Publication number
- CN106127052A CN106127052A CN201610509383.4A CN201610509383A CN106127052A CN 106127052 A CN106127052 A CN 106127052A CN 201610509383 A CN201610509383 A CN 201610509383A CN 106127052 A CN106127052 A CN 106127052A
- Authority
- CN
- China
- Prior art keywords
- file
- monitored
- file format
- rogue program
- format
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
- 238000000034 method Methods 0.000 title claims abstract description 89
- 230000008569 process Effects 0.000 claims description 35
- 238000012544 monitoring process Methods 0.000 claims description 25
- 230000008859 change Effects 0.000 claims description 9
- 238000012986 modification Methods 0.000 claims description 3
- 230000004048 modification Effects 0.000 claims description 3
- 230000000875 corresponding effect Effects 0.000 description 8
- 238000006243 chemical reaction Methods 0.000 description 7
- 230000002265 prevention Effects 0.000 description 6
- ZXQYGBMAQZUVMI-GCMPRSNUSA-N gamma-cyhalothrin Chemical class CC1(C)[C@@H](\C=C(/Cl)C(F)(F)F)[C@H]1C(=O)O[C@H](C#N)C1=CC=CC(OC=2C=CC=CC=2)=C1 ZXQYGBMAQZUVMI-GCMPRSNUSA-N 0.000 description 5
- 230000006870 function Effects 0.000 description 4
- 230000008901 benefit Effects 0.000 description 3
- 238000010586 diagram Methods 0.000 description 3
- 230000005540 biological transmission Effects 0.000 description 2
- 238000000151 deposition Methods 0.000 description 2
- 238000012545 processing Methods 0.000 description 2
- 101100010303 Drosophila melanogaster PolG1 gene Proteins 0.000 description 1
- 101150078890 POLG gene Proteins 0.000 description 1
- 230000016571 aggressive behavior Effects 0.000 description 1
- 238000004590 computer program Methods 0.000 description 1
- 230000002596 correlated effect Effects 0.000 description 1
- 230000006837 decompression Effects 0.000 description 1
- 238000012217 deletion Methods 0.000 description 1
- 230000037430 deletion Effects 0.000 description 1
- 238000013461 design Methods 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 238000001035 drying Methods 0.000 description 1
- 230000001960 triggered effect Effects 0.000 description 1
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Virology (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
Abstract
Description
Claims (10)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201610509383.4A CN106127052B (zh) | 2016-06-30 | 2016-06-30 | 恶意程序的识别方法及装置 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201610509383.4A CN106127052B (zh) | 2016-06-30 | 2016-06-30 | 恶意程序的识别方法及装置 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN106127052A true CN106127052A (zh) | 2016-11-16 |
CN106127052B CN106127052B (zh) | 2019-05-14 |
Family
ID=57468923
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201610509383.4A Active CN106127052B (zh) | 2016-06-30 | 2016-06-30 | 恶意程序的识别方法及装置 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN106127052B (zh) |
Cited By (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN108717509A (zh) * | 2018-06-05 | 2018-10-30 | 厦门安胜网络科技有限公司 | 一种在沙箱中提取程序衍生物的方法、装置、设备及可读介质 |
CN113987016A (zh) * | 2021-10-25 | 2022-01-28 | 浙江太美医疗科技股份有限公司 | 临床递交数据对比方法、装置、计算机设备和存储介质 |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20020174349A1 (en) * | 2001-05-15 | 2002-11-21 | Wolff Daniel Joseph | Detecting malicious alteration of stored computer files |
US20110072262A1 (en) * | 2009-09-23 | 2011-03-24 | Idan Amir | System and Method for Identifying Security Breach Attempts of a Website |
CN103544437A (zh) * | 2012-12-27 | 2014-01-29 | 哈尔滨安天科技股份有限公司 | 一种基于扩展名和文件格式一致性的安全判别方法和装置 |
CN103593612A (zh) * | 2013-11-08 | 2014-02-19 | 北京奇虎科技有限公司 | 一种处理恶意程序的方法及装置 |
-
2016
- 2016-06-30 CN CN201610509383.4A patent/CN106127052B/zh active Active
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20020174349A1 (en) * | 2001-05-15 | 2002-11-21 | Wolff Daniel Joseph | Detecting malicious alteration of stored computer files |
US20110072262A1 (en) * | 2009-09-23 | 2011-03-24 | Idan Amir | System and Method for Identifying Security Breach Attempts of a Website |
CN103544437A (zh) * | 2012-12-27 | 2014-01-29 | 哈尔滨安天科技股份有限公司 | 一种基于扩展名和文件格式一致性的安全判别方法和装置 |
CN103593612A (zh) * | 2013-11-08 | 2014-02-19 | 北京奇虎科技有限公司 | 一种处理恶意程序的方法及装置 |
Cited By (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN108717509A (zh) * | 2018-06-05 | 2018-10-30 | 厦门安胜网络科技有限公司 | 一种在沙箱中提取程序衍生物的方法、装置、设备及可读介质 |
CN108717509B (zh) * | 2018-06-05 | 2020-06-23 | 厦门安胜网络科技有限公司 | 一种在沙箱中提取程序衍生物的方法、装置、设备及可读介质 |
CN113987016A (zh) * | 2021-10-25 | 2022-01-28 | 浙江太美医疗科技股份有限公司 | 临床递交数据对比方法、装置、计算机设备和存储介质 |
CN113987016B (zh) * | 2021-10-25 | 2023-08-15 | 上海太美数字科技有限公司 | 临床递交数据对比方法、装置、计算机设备和存储介质 |
Also Published As
Publication number | Publication date |
---|---|
CN106127052B (zh) | 2019-05-14 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US9047466B2 (en) | Method of detecting a malware based on a white list | |
US9916230B1 (en) | White box testing | |
CN103473501B (zh) | 一种基于云安全的恶意软件追踪方法 | |
US20150220332A1 (en) | Resolving merge conflicts that prevent blocks of program code from properly being merged | |
US11321274B2 (en) | Software discovery with variable scan frequency | |
KR20160125960A (ko) | 바이러스 처리 방법, 장치, 시스템 및 기기, 및 컴퓨터 저장 매체 | |
CN102629310A (zh) | 用于保护计算机系统免遭恶意对象活动侵害的系统和方法 | |
EP3428828A1 (en) | System and method for locating and correcting vulnerabilites in a target computer system | |
US11777970B1 (en) | Granular and prioritized visualization of anomalous log data | |
CN108664801B (zh) | 一种结合机器学习的数据防泄漏策略动态更新方法及装置 | |
CN116226865A (zh) | 云原生应用的安全检测方法、装置、服务器、介质及产品 | |
CN106127052A (zh) | 恶意程序的识别方法及装置 | |
US11283836B2 (en) | Automatic decoy derivation through patch transformation | |
US20200042317A1 (en) | Self-learning automated techniques for detecting the usage of software packages | |
CN102982043B (zh) | Pe文件的处理方法和装置 | |
US10102204B2 (en) | Maintaining access control lists in non-identity-preserving replicated data repositories | |
CN104243604A (zh) | 一种文件禁用的方法及装置 | |
US10552241B2 (en) | Action recommendation to reduce server management errors | |
KR101986498B1 (ko) | 전자전 장비의 로그파일을 관리하는 로그파일 관리시스템 및 방법 | |
US8756649B2 (en) | Language-agnostic policy management | |
KR102101041B1 (ko) | 보안 통제 장치 및 이의 작동 방법 | |
US11681805B1 (en) | System for analytic data memorialization, data science, and validation | |
CN103984902A (zh) | 一种新增数据资产的识别方法和系统 | |
US20230140706A1 (en) | Pipelined Malware Infrastructure Identification | |
CN115454808A (zh) | 待上线文件控制方法、系统和电子设备 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
GR01 | Patent grant | ||
GR01 | Patent grant | ||
TR01 | Transfer of patent right | ||
TR01 | Transfer of patent right |
Effective date of registration: 20211202 Address after: 300450 No. 9-3-401, No. 39, Gaoxin 6th Road, Binhai Science Park, high tech Zone, Binhai New Area, Tianjin Patentee after: 3600 Technology Group Co.,Ltd. Address before: 100088 room 112, block D, 28 new street, new street, Xicheng District, Beijing (Desheng Park) Patentee before: BEIJING QIHOO TECHNOLOGY Co.,Ltd. Patentee before: Qizhi software (Beijing) Co.,Ltd. |
|
TR01 | Transfer of patent right | ||
TR01 | Transfer of patent right |
Effective date of registration: 20230710 Address after: 1765, floor 17, floor 15, building 3, No. 10 Jiuxianqiao Road, Chaoyang District, Beijing 100015 Patentee after: Beijing Hongxiang Technical Service Co.,Ltd. Address before: 300450 No. 9-3-401, No. 39, Gaoxin 6th Road, Binhai Science Park, high tech Zone, Binhai New Area, Tianjin Patentee before: 3600 Technology Group Co.,Ltd. |
|
CP03 | Change of name, title or address |
Address after: 1765, floor 17, floor 15, building 3, No. 10 Jiuxianqiao Road, Chaoyang District, Beijing 100015 Patentee after: Beijing 360 Zhiling Technology Co.,Ltd. Country or region after: China Address before: 1765, floor 17, floor 15, building 3, No. 10 Jiuxianqiao Road, Chaoyang District, Beijing 100015 Patentee before: Beijing Hongxiang Technical Service Co.,Ltd. Country or region before: China |