CN108182363B - 嵌入式office文档的检测方法、系统及存储介质 - Google Patents
嵌入式office文档的检测方法、系统及存储介质 Download PDFInfo
- Publication number
- CN108182363B CN108182363B CN201711417945.3A CN201711417945A CN108182363B CN 108182363 B CN108182363 B CN 108182363B CN 201711417945 A CN201711417945 A CN 201711417945A CN 108182363 B CN108182363 B CN 108182363B
- Authority
- CN
- China
- Prior art keywords
- file
- newly added
- malicious
- office
- executable
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/562—Static detection
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Virology (AREA)
- Health & Medical Sciences (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- General Health & Medical Sciences (AREA)
- Debugging And Monitoring (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
Description
Claims (5)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201711417945.3A CN108182363B (zh) | 2017-12-25 | 2017-12-25 | 嵌入式office文档的检测方法、系统及存储介质 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201711417945.3A CN108182363B (zh) | 2017-12-25 | 2017-12-25 | 嵌入式office文档的检测方法、系统及存储介质 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN108182363A CN108182363A (zh) | 2018-06-19 |
CN108182363B true CN108182363B (zh) | 2022-01-07 |
Family
ID=62546948
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201711417945.3A Active CN108182363B (zh) | 2017-12-25 | 2017-12-25 | 嵌入式office文档的检测方法、系统及存储介质 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN108182363B (zh) |
Families Citing this family (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN110717180B (zh) * | 2018-07-13 | 2021-09-28 | 北京安天网络安全技术有限公司 | 基于自定位行为的恶意文档检测方法、系统及存储介质 |
CN110866252A (zh) * | 2018-12-21 | 2020-03-06 | 北京安天网络安全技术有限公司 | 一种恶意代码检测方法、装置、电子设备及存储介质 |
CN109905396A (zh) * | 2019-03-11 | 2019-06-18 | 北京奇艺世纪科技有限公司 | 一种WebShell文件检测方法、装置及电子设备 |
CN110443051B (zh) * | 2019-07-30 | 2022-12-27 | 空气动力学国家重点实验室 | 一种防止涉密文档在互联网传播的方法 |
Citations (8)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
EP2237186A2 (en) * | 2009-03-30 | 2010-10-06 | Kaspersky Lab Zao | Method for accelerating hardware emulator used for malware detection and analysis |
CN103902908A (zh) * | 2013-12-25 | 2014-07-02 | 武汉安天信息技术有限责任公司 | 一种对Android加固应用的恶意代码检测方法及系统 |
CN103970574A (zh) * | 2014-05-22 | 2014-08-06 | 北京奇虎科技有限公司 | office程序的运行方法及装置、计算机系统 |
CN104657637A (zh) * | 2015-01-29 | 2015-05-27 | 深信服网络科技(深圳)有限公司 | 文档信息嵌入、追踪方法和系统及代理服务设备 |
CN104765682A (zh) * | 2015-03-30 | 2015-07-08 | 微梦创科网络科技(中国)有限公司 | 跨站脚本漏洞的线下检测方法和系统 |
CN105117648A (zh) * | 2015-07-29 | 2015-12-02 | 杭州安恒信息技术有限公司 | 一种基于虚拟机的0day/恶意文档检测系统及方法 |
CN106919840A (zh) * | 2017-03-03 | 2017-07-04 | 努比亚技术有限公司 | 一种恶意软件的检测方法及装置 |
CN107025407A (zh) * | 2017-03-22 | 2017-08-08 | 国家计算机网络与信息安全管理中心 | 一种office文档文件的恶意代码检测方法及系统 |
Family Cites Families (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN103902855B (zh) * | 2013-12-17 | 2017-03-08 | 哈尔滨安天科技股份有限公司 | 一种文件篡改检测及修复的方法和系统 |
-
2017
- 2017-12-25 CN CN201711417945.3A patent/CN108182363B/zh active Active
Patent Citations (8)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
EP2237186A2 (en) * | 2009-03-30 | 2010-10-06 | Kaspersky Lab Zao | Method for accelerating hardware emulator used for malware detection and analysis |
CN103902908A (zh) * | 2013-12-25 | 2014-07-02 | 武汉安天信息技术有限责任公司 | 一种对Android加固应用的恶意代码检测方法及系统 |
CN103970574A (zh) * | 2014-05-22 | 2014-08-06 | 北京奇虎科技有限公司 | office程序的运行方法及装置、计算机系统 |
CN104657637A (zh) * | 2015-01-29 | 2015-05-27 | 深信服网络科技(深圳)有限公司 | 文档信息嵌入、追踪方法和系统及代理服务设备 |
CN104765682A (zh) * | 2015-03-30 | 2015-07-08 | 微梦创科网络科技(中国)有限公司 | 跨站脚本漏洞的线下检测方法和系统 |
CN105117648A (zh) * | 2015-07-29 | 2015-12-02 | 杭州安恒信息技术有限公司 | 一种基于虚拟机的0day/恶意文档检测系统及方法 |
CN106919840A (zh) * | 2017-03-03 | 2017-07-04 | 努比亚技术有限公司 | 一种恶意软件的检测方法及装置 |
CN107025407A (zh) * | 2017-03-22 | 2017-08-08 | 国家计算机网络与信息安全管理中心 | 一种office文档文件的恶意代码检测方法及系统 |
Also Published As
Publication number | Publication date |
---|---|
CN108182363A (zh) | 2018-06-19 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN108763928B (zh) | 一种开源软件漏洞分析方法、装置和存储介质 | |
CN108182363B (zh) | 嵌入式office文档的检测方法、系统及存储介质 | |
EP3506139B1 (en) | Malware detection in event loops | |
US9922193B2 (en) | Identifying an evasive malicious object based on a behavior delta | |
US10397261B2 (en) | Identifying device, identifying method and identifying program | |
US9824212B2 (en) | Method and system for recognizing advertisement plug-ins | |
US8955124B2 (en) | Apparatus, system and method for detecting malicious code | |
KR101554633B1 (ko) | 악성 코드 검출 장치 및 그 방법 | |
CN108182364B (zh) | 一种基于调用依赖关系识别攻击同源的方法及系统 | |
US9910983B2 (en) | Malware detection | |
WO2017012241A1 (zh) | 文件的检测方法、装置、设备及非易失性计算机存储介质 | |
JP6000465B2 (ja) | プロセス検査装置、プロセス検査プログラムおよびプロセス検査方法 | |
CN107818107B (zh) | 控制页面跳转的方法和装置 | |
KR20100005518A (ko) | 확장자를 위장한 파일을 탐지하는 방법 및 그 장치 | |
US20180285565A1 (en) | Malware detection in applications based on presence of computer generated strings | |
CN108229168B (zh) | 一种嵌套类文件的启发式检测方法、系统及存储介质 | |
KR102292844B1 (ko) | 악성코드 탐지 장치 및 방법 | |
JP2015132942A (ja) | 接続先情報判定装置、接続先情報判定方法、及びプログラム | |
CN106778276B (zh) | 一种检测无实体文件恶意代码的方法及系统 | |
CN110377499B (zh) | 一种对应用程序进行测试的方法及装置 | |
JP5667957B2 (ja) | マルウェア検知装置およびプログラム | |
CN109472141B (zh) | 一种基于时间序列化差异检测恶意代码的方法及系统 | |
CN112434287A (zh) | 一种检测Hook的方法、装置、设备及存储介质 | |
US20190080090A1 (en) | Method and apparatus for detecting dynamically-loaded malware with run time predictive analysis | |
JP2016122262A (ja) | 特定装置、特定方法および特定プログラム |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
CB02 | Change of applicant information | ||
CB02 | Change of applicant information |
Address after: 150028 Building 7, Innovation Plaza, Science and Technology Innovation City, Harbin Hi-tech Industrial Development Zone, Heilongjiang Province (838 Shikun Road) Applicant after: Harbin antiy Technology Group Limited by Share Ltd Address before: 150090 Room 506, No. 162 Hongqi Street, Nangang District, Harbin Development Zone, Heilongjiang Province Applicant before: Harbin Antiy Technology Co., Ltd. |
|
CB02 | Change of applicant information | ||
CB02 | Change of applicant information |
Address after: 150028 building 7, innovation and entrepreneurship square, science and technology innovation city, Harbin high tech Industrial Development Zone, Heilongjiang Province (No. 838, Shikun Road) Applicant after: Antan Technology Group Co.,Ltd. Address before: 150028 building 7, innovation and entrepreneurship square, science and technology innovation city, Harbin high tech Industrial Development Zone, Heilongjiang Province (No. 838, Shikun Road) Applicant before: Harbin Antian Science and Technology Group Co.,Ltd. |
|
GR01 | Patent grant | ||
GR01 | Patent grant |