KR20090088198A - 커널 모드의 악성 행위 검출 시스템 및 그 방법 - Google Patents
커널 모드의 악성 행위 검출 시스템 및 그 방법 Download PDFInfo
- Publication number
- KR20090088198A KR20090088198A KR1020080013596A KR20080013596A KR20090088198A KR 20090088198 A KR20090088198 A KR 20090088198A KR 1020080013596 A KR1020080013596 A KR 1020080013596A KR 20080013596 A KR20080013596 A KR 20080013596A KR 20090088198 A KR20090088198 A KR 20090088198A
- Authority
- KR
- South Korea
- Prior art keywords
- kernel mode
- address
- function
- memory
- arbitrary
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/562—Static detection
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Virology (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims (13)
- 커널(Kernel) 모드의 악성 행위 검출 시스템에 있어서,임의의 커널 모드 드라이버에 대한 실행 이미지 파일 및 객체 정보를 전달받아 상기 임의의 커널 모드 드라이버를 메모리에 로드하여 가상으로 구동하고, 상기 임의의 커널 모드 드라이버의 가상 구동에 따라 산출되는 디스패처(Dispatcher) 함수의 상기 메모리 상 주소 정보를 반환하는 커널 모드 가상 실행 모듈; 및상기 임의의 커널 모드 드라이버에 대한 객체 정보를 토대로 상기 임의의 커널 모드 드라이버의 실제 구동에 따라 산출되는 디스패처 함수의 메모리 상의 실제 주소를 파악하며, 상기 파악된 상기 디스패처 함수의 실제 주소 정보와 상기 커널 모드 가상 실행 모듈로부터 반환되는 주소 정보를 비교하여 상이할 경우, 상기 디스패처 함수의 주소를 상기 반환된 주소 정보로 변경하는 커널 모드 객체 제어 모듈을 포함하는 것을 특징으로 하는 커널 모드의 악성 행위 검출 시스템.
- 제 1 항에 있어서, 상기 시스템은,상기 임의의 커널 모드 드라이버에 대한 실행 이미지 파일 및 객체 정보를 제공하며, 상기 커널 모드 가상 실행 모듈로부터 반환되는 디스패처 함수의 주소 정보를 상기 커널 모드 객체 제어 모듈로 전달하는 제어 모듈을 더 포함하는 것을 특징으로 하는 커널 모드의 악성 행위 검출 시스템.
- 제 1 항에 있어서, 상기 커널 모드 가상 실행 모듈은,상기 실행 이미지 파일의 크기와 동일한 크기의 메모리를 할당하여 상기 실행 이미지를 로딩하며, 상기 메모리의 시작 주소를 기준으로 상기 로딩된 실행 이미지에 대한 실행 명령의 주소 값을 재배치하는 것을 특징으로 하는 커널 모드의 악성 행위 검출 시스템.
- 제 3 항에 있어서, 상기 커널 모드 가상 실행 모듈은,IAT(Import Address Table)의 함수 목록을 검색하여 지원 가능한 함수를 선별하고, 상기 선별된 함수의 주소를 자체 처리를 위한 지원 대상 주소로 변환하여 상기 메모리에 저장하는 것을 특징으로 하는 커널 모드의 악성 행위 검출 시스템.
- 제 4 항에 있어서, 상기 커널 모드 가상 실행 모듈은,상기 객체 정보에 포함된 상기 임의의 커널 모드 드라이버의 구동에 따른 호출 대상 함수 목록을 토대로, 해당 함수의 상기 지원 대상 주소를 상기 메모리 상의 실제 함수 주소로 변경하는 것을 특징으로 하는 커널 모드의 악성 행위 검출 시스템.
- 제 5 항에 있어서, 상기 커널 모드 가상 실행 모듈은,상기 객체 정보에 포함된 인수 정보를 통해 메모리 상의 실제 함수 주소로 변환된 상기 해당 함수의 실행 명령을 실행하는 것을 특징으로 하는 커널 모드의 악성 행위 검출 시스템.
- 제 1 항에 있어서, 상기 커널 모드 객체 제어 모듈은,상기 객체 정보에 포함된 상기 임의의 커널 모드 드라이버에 대한 이름 정보를 토대로 상기 임의의 커널 모드 드라이버에 대한 실제 구동에 따른 메모리 상의 로딩 위치를 확인하여 상기 임의의 커널 모드 드라이버의 실제 구동에 따라 산출되는 상기 디스패처 함수의 메모리 상의 실제 주소를 파악하는 것을 특징으로 하는 커널 모드의 악성 행위 검출 시스템.
- 제 1 항에 있어서, 상기 커널 모드 객체 제어 모듈은,상기 파악된 상기 디스패처 함수의 실제 주소 정보와 상기 커널 모드 가상 실행 모듈로부터 반환되는 주소 정보를 동일 기준의 절대 주소로 변환하여 상호 비교하는 것을 특징으로 하는 커널 모드의 악성 행위 검출 시스템.
- 커널(Kernel) 모드의 악성 행위 검출 방법에 있어서,a) 임의의 커널 모드 드라이버에 대한 실행 이미지 파일 및 객체 정보를 전달받아 상기 임의의 커널 모드 드라이버를 메모리에 로드하여 가상으로 구동하는 단계;b) 상기 임의의 커널 모드 드라이버의 가상 구동에 따라 산출되는 디스패처(Dispatcher) 함수의 상기 메모리 상의 주소 정보를 반환하는 단계;c) 상기 임의의 커널 모드 드라이버에 대한 객체 정보를 토대로 상기 임의의 커널 모드 드라이버의 실제 구동에 따라 산출되는 디스패처 함수의 메모리 상의 실제 주소를 파악하는 단계; 및d) 상기 파악된 상기 디스패처 함수의 실제 주소 정보와 상기 커널 모드 가상 실행 모듈로부터 반환되는 주소 정보를 비교하는 단계를 포함하는 것을 특징으로 하는 커널 모드의 악성 행위 검출 방법.
- 제 9 항에 있어서, 상기 방법은,e) 상기 'd) 단계'를 통한 비교 결과, 상이할 경우 상기 디스패처 함수의 주소를 상기 반환된 주소 정보로 변경하는 단계를 더 포함하는 것을 특징으로 하는 커널 모드의 악성 행위 검출 방법.
- 제 9 항에 있어서, 상기 a) 단계는,a-1) 상기 실행 이미지 파일의 크기와 동일한 크기의 메모리를 할당하여 상기 실행 이미지를 로딩하는 단계;a-2) 상기 메모리의 시작 주소를 기준으로 상기 로딩된 실행 이미지에 대한 실행 명령의 주소 값을 재배치하는 단계;a-3) IAT(Import Address Table)의 함수 목록을 검색하여 지원 가능한 함수를 선별하는 단계;a-4) 상기 선별된 함수의 주소를 자체 처리를 위한 지원 대상 주소로 변환하 여 상기 메모리에 저장하는 단계;a-5) 상기 객체 정보에 포함된 상기 임의의 커널 모드 드라이버의 구동에 따른 호출 대상 함수 목록을 토대로, 해당 함수의 상기 지원 대상 주소를 상기 메모리 상의 실제 함수 주소로 변경하는 단계; 및a-6) 상기 객체 정보에 포함된 인수 정보를 통해 메모리 상의 실제 함수 주소로 변환된 상기 해당 함수의 실행 명령을 실행하는 단계를 포함하는 것을 특징으로 하는 커널 모드의 악성 행위 검출 방법.
- 제 9 항에 있어서, 상기 c) 단계는,c-1) 상기 객체 정보에 포함된 상기 임의의 커널 모드 드라이버에 대한 이름 정보를 토대로 상기 임의의 커널 모드 드라이버의 실제 구동에 따른 메모리 상의 로딩 위치를 확인하는 단계; 및c-2) 상기 확인된 메모리 상의 로딩 위치를 토대로, 상기 임의의 커널 모드 드라이버의 실제 구동에 따라 산출되는 상기 디스패처 함수의 메모리 상의 실제 주소를 파악하는 단계를 포함하는 것을 특징으로 하는 커널 모드의 악성 행위 검출 방법.
- 제 10 항에 있어서, 상기 d) 단계는,상기 파악된 상기 디스패처 함수의 실제 주소 정보와 상기 커널 모드 가상 실행 모듈로부터 반환되는 주소 정보를 동일 기준의 절대 주소로 변환하여 상호 비 교하는 것을 특징으로 하는 커널 모드의 악성 행위 검출 방법.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR1020080013596A KR100925401B1 (ko) | 2008-02-14 | 2008-02-14 | 커널 모드의 악성 행위 검출 시스템 및 그 방법 |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR1020080013596A KR100925401B1 (ko) | 2008-02-14 | 2008-02-14 | 커널 모드의 악성 행위 검출 시스템 및 그 방법 |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| KR20090088198A true KR20090088198A (ko) | 2009-08-19 |
| KR100925401B1 KR100925401B1 (ko) | 2009-11-09 |
Family
ID=41206958
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| KR1020080013596A Active KR100925401B1 (ko) | 2008-02-14 | 2008-02-14 | 커널 모드의 악성 행위 검출 시스템 및 그 방법 |
Country Status (1)
| Country | Link |
|---|---|
| KR (1) | KR100925401B1 (ko) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20260037628A1 (en) * | 2024-07-31 | 2026-02-05 | Palo Alto Networks (Israel Analytics) Ltd. | Malicious Direct Syscall Call Detection |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR101097590B1 (ko) * | 2011-07-15 | 2011-12-22 | 오영광 | 동적 링크 라이브러리 인젝션 방어 방법 |
Family Cites Families (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR20020097344A (ko) * | 2001-06-20 | 2002-12-31 | 주식회사 마이크로모스 | 컴퓨터 하드디스크 내 자료 복구 방법 |
| KR100786725B1 (ko) * | 2005-11-08 | 2007-12-21 | 한국정보보호진흥원 | 악성코드 분석 시스템 및 방법 |
-
2008
- 2008-02-14 KR KR1020080013596A patent/KR100925401B1/ko active Active
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20260037628A1 (en) * | 2024-07-31 | 2026-02-05 | Palo Alto Networks (Israel Analytics) Ltd. | Malicious Direct Syscall Call Detection |
| US12625961B2 (en) * | 2024-07-31 | 2026-05-12 | Palo Alto Networks, Inc. | Malicious direct syscall call detection |
Also Published As
| Publication number | Publication date |
|---|---|
| KR100925401B1 (ko) | 2009-11-09 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US8909913B2 (en) | Method for integrating heterogeneous operating systems based on the same system kernel using a shared information area accessible to multiple operating systems | |
| KR101493076B1 (ko) | 버퍼 오버플로우 관리를 통한 바이러스 코드 실행방지장치 및 그 방법 | |
| US7574624B2 (en) | Integrated test method on multi-operating system platform | |
| US9158562B2 (en) | Method and apparatus for supporting virtualization of loadable module | |
| US20180357068A1 (en) | Method And System For Automated Agent Injection In Container Environments | |
| US20170103206A1 (en) | Method and apparatus for capturing operation in a container-based virtualization system | |
| KR100704629B1 (ko) | 변경된 위치의 마스터 부트 레코드의 바이러스 감염 여부를판단하고 치료하는 장치 및 방법 | |
| CN102024113B (zh) | 快速检测恶意代码的方法和系统 | |
| CN113051088B (zh) | 程序加载方法、装置、设备及计算机可读介质 | |
| US20130096880A1 (en) | System test method | |
| US12475053B2 (en) | Method for detecting error of operating system kernel memory in real time | |
| US7814471B2 (en) | Method and apparatus for providing DLL compatibility | |
| CN105678160B (zh) | 用于提供对引导驱动程序的原始例程的访问的系统和方法 | |
| Cui et al. | Tracking rootkit footprints with a practical memory analysis system | |
| US20150324580A1 (en) | Apparatus and method for analyzing malicious code in real environment | |
| CN111399988B (zh) | 一种云平台的内存安全检测系统及方法 | |
| TWI656453B (zh) | 檢測系統及檢測方法 | |
| US10372472B2 (en) | System, method, and computer program product for conditionally preventing use of hardware virtualization | |
| JP4903149B2 (ja) | コンピュータシステム上でコンピュータプログラムを処理する方法 | |
| KR100925401B1 (ko) | 커널 모드의 악성 행위 검출 시스템 및 그 방법 | |
| JP2018081514A (ja) | マルウェアの解析方法及び記憶媒体 | |
| TWI450090B (zh) | 關於改變程式之啟動列表以判定電腦系統性能是否增進之方法及系統 | |
| CN119645872A (zh) | 一种针对闭源操作系统的模糊测试方法及装置 | |
| US12135690B2 (en) | Method for processing a system image | |
| KR101052735B1 (ko) | 메모리 조작유무를 감지하는 방법 및 이를 이용한 장치 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| A201 | Request for examination | ||
| PA0109 | Patent application |
St.27 status event code: A-0-1-A10-A12-nap-PA0109 |
|
| PA0201 | Request for examination |
St.27 status event code: A-1-2-D10-D11-exm-PA0201 |
|
| D13-X000 | Search requested |
St.27 status event code: A-1-2-D10-D13-srh-X000 |
|
| D14-X000 | Search report completed |
St.27 status event code: A-1-2-D10-D14-srh-X000 |
|
| E902 | Notification of reason for refusal | ||
| PE0902 | Notice of grounds for rejection |
St.27 status event code: A-1-2-D10-D21-exm-PE0902 |
|
| P11-X000 | Amendment of application requested |
St.27 status event code: A-2-2-P10-P11-nap-X000 |
|
| P13-X000 | Application amended |
St.27 status event code: A-2-2-P10-P13-nap-X000 |
|
| PG1501 | Laying open of application |
St.27 status event code: A-1-1-Q10-Q12-nap-PG1501 |
|
| E701 | Decision to grant or registration of patent right | ||
| PE0701 | Decision of registration |
St.27 status event code: A-1-2-D10-D22-exm-PE0701 |
|
| GRNT | Written decision to grant | ||
| PR0701 | Registration of establishment |
St.27 status event code: A-2-4-F10-F11-exm-PR0701 |
|
| PR1002 | Payment of registration fee |
St.27 status event code: A-2-2-U10-U11-oth-PR1002 Fee payment year number: 1 |
|
| PG1601 | Publication of registration |
St.27 status event code: A-4-4-Q10-Q13-nap-PG1601 |
|
| R18-X000 | Changes to party contact information recorded |
St.27 status event code: A-5-5-R10-R18-oth-X000 |
|
| R18-X000 | Changes to party contact information recorded |
St.27 status event code: A-5-5-R10-R18-oth-X000 |
|
| PN2301 | Change of applicant |
St.27 status event code: A-5-5-R10-R13-asn-PN2301 St.27 status event code: A-5-5-R10-R11-asn-PN2301 |
|
| FPAY | Annual fee payment |
Payment date: 20121030 Year of fee payment: 4 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 4 |
|
| FPAY | Annual fee payment |
Payment date: 20131030 Year of fee payment: 5 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 5 |
|
| R18-X000 | Changes to party contact information recorded |
St.27 status event code: A-5-5-R10-R18-oth-X000 |
|
| FPAY | Annual fee payment |
Payment date: 20141030 Year of fee payment: 6 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 6 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 7 |
|
| P22-X000 | Classification modified |
St.27 status event code: A-4-4-P10-P22-nap-X000 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 8 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 9 |
|
| R18-X000 | Changes to party contact information recorded |
St.27 status event code: A-5-5-R10-R18-oth-X000 |
|
| R18-X000 | Changes to party contact information recorded |
St.27 status event code: A-5-5-R10-R18-oth-X000 |
|
| R18-X000 | Changes to party contact information recorded |
St.27 status event code: A-5-5-R10-R18-oth-X000 |
|
| FPAY | Annual fee payment |
Payment date: 20181030 Year of fee payment: 10 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 10 |
|
| FPAY | Annual fee payment |
Payment date: 20191030 Year of fee payment: 11 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 11 |
|
| R18-X000 | Changes to party contact information recorded |
St.27 status event code: A-5-5-R10-R18-oth-X000 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 12 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 13 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 14 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 15 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 16 |
|
| P14-X000 | Amendment of ip right document requested |
St.27 status event code: A-5-5-P10-P14-nap-X000 |
|
| R18-X000 | Changes to party contact information recorded |
St.27 status event code: A-5-5-R10-R18-oth-X000 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 17 |
|
| U11 | Full renewal or maintenance fee paid |
Free format text: ST27 STATUS EVENT CODE: A-4-4-U10-U11-OTH-PR1001 (AS PROVIDED BY THE NATIONAL OFFICE) Year of fee payment: 17 |