WO2010035957A3 - 은폐된 시스템 개체 진단 시스템 및 진단 방법 - Google Patents

은폐된 시스템 개체 진단 시스템 및 진단 방법 Download PDF

Info

Publication number
WO2010035957A3
WO2010035957A3 PCT/KR2009/004547 KR2009004547W WO2010035957A3 WO 2010035957 A3 WO2010035957 A3 WO 2010035957A3 KR 2009004547 W KR2009004547 W KR 2009004547W WO 2010035957 A3 WO2010035957 A3 WO 2010035957A3
Authority
WO
WIPO (PCT)
Prior art keywords
hidden
entity
system entity
diagnosis
enumeration
Prior art date
Application number
PCT/KR2009/004547
Other languages
English (en)
French (fr)
Other versions
WO2010035957A2 (ko
Inventor
김성현
고항훈
Original Assignee
주식회사 안철수연구소
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 주식회사 안철수연구소 filed Critical 주식회사 안철수연구소
Publication of WO2010035957A2 publication Critical patent/WO2010035957A2/ko
Publication of WO2010035957A3 publication Critical patent/WO2010035957A3/ko

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/56Computer malware detection or handling, e.g. anti-virus arrangements
    • G06F21/566Dynamic detection, i.e. detection performed at run-time, e.g. emulation, suspicious activities
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/30Monitoring
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/554Detecting local intrusion or implementing counter-measures involving event detection and direct action
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/56Computer malware detection or handling, e.g. anti-virus arrangements
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Health & Medical Sciences (AREA)
  • General Health & Medical Sciences (AREA)
  • Virology (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Quality & Reliability (AREA)
  • Debugging And Monitoring (AREA)
  • Storage Device Security (AREA)

Abstract

본 발명은 은폐형 악성코드가 안티 바이러스 등에서 검색되지 않도록 하기 위해서 은폐한 시스템 개체를 찾아내기 위한 은폐된 시스템 개체 진단 시스템 및 진단 방법에 관한 것이다. 본 발명에 따른 은폐된 시스템 개체 진단 시스템은 운영체제가 제공하는 열거 API를 호출하는 기능을 수행하는 열거모듈; 운영체제의 커널영역에 설치되며, 커널영역에서 시스템개체의 I/O를 감시하는 필터 및 상기 필터에서 시스템개체의 I/O 가 발생한 경우, 상기 시스템개체의 정보를 열거모듈에 제공하고, 상기 시스템개체가 열거모듈에서 검색이 되는지 여부를 기초로 시스템개체의 은폐여부를 판단하는 제어모듈을 포함한다.
PCT/KR2009/004547 2008-09-25 2009-08-14 은폐된 시스템 개체 진단 시스템 및 진단 방법 WO2010035957A2 (ko)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
KR10-2008-0094345 2008-09-25
KR1020080094345A KR101001899B1 (ko) 2008-09-25 2008-09-25 은폐된 시스템 개체 진단 시스템 및 진단 방법

Publications (2)

Publication Number Publication Date
WO2010035957A2 WO2010035957A2 (ko) 2010-04-01
WO2010035957A3 true WO2010035957A3 (ko) 2010-07-01

Family

ID=42060222

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/KR2009/004547 WO2010035957A2 (ko) 2008-09-25 2009-08-14 은폐된 시스템 개체 진단 시스템 및 진단 방법

Country Status (2)

Country Link
KR (1) KR101001899B1 (ko)
WO (1) WO2010035957A2 (ko)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR102174393B1 (ko) * 2020-08-13 2020-11-04 최원강 악성 코드 탐지 장치
US11762812B2 (en) 2021-12-10 2023-09-19 Microsoft Technology Licensing, Llc Detecting changes in a namespace using namespace enumeration endpoint response payloads

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20040025015A1 (en) * 2002-01-04 2004-02-05 Internet Security Systems System and method for the managed security control of processes on a computer system
KR100666562B1 (ko) * 2005-08-11 2007-01-09 주식회사 웨어플러스 커널 드라이버 및 프로세스 보호 방법
US20070022287A1 (en) * 2005-07-15 2007-01-25 Microsoft Corporation Detecting user-mode rootkits
KR20070076935A (ko) * 2006-01-20 2007-07-25 엔에이치엔(주) 은닉 프로세스 모니터링 방법 및 모니터링 시스템
KR20070121195A (ko) * 2006-06-21 2007-12-27 한국전자통신연구원 시스템 이벤트 정보를 이용한 은닉 프로세스 탐지 시스템및 방법
US20080016571A1 (en) * 2006-07-11 2008-01-17 Larry Chung Yao Chang Rootkit detection system and method

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8028301B2 (en) 2005-03-14 2011-09-27 Symantec Corporation Restricting recordal of user activity in a processing system

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20040025015A1 (en) * 2002-01-04 2004-02-05 Internet Security Systems System and method for the managed security control of processes on a computer system
US20070022287A1 (en) * 2005-07-15 2007-01-25 Microsoft Corporation Detecting user-mode rootkits
KR100666562B1 (ko) * 2005-08-11 2007-01-09 주식회사 웨어플러스 커널 드라이버 및 프로세스 보호 방법
KR20070076935A (ko) * 2006-01-20 2007-07-25 엔에이치엔(주) 은닉 프로세스 모니터링 방법 및 모니터링 시스템
KR20070121195A (ko) * 2006-06-21 2007-12-27 한국전자통신연구원 시스템 이벤트 정보를 이용한 은닉 프로세스 탐지 시스템및 방법
US20080016571A1 (en) * 2006-07-11 2008-01-17 Larry Chung Yao Chang Rootkit detection system and method

Also Published As

Publication number Publication date
KR101001899B1 (ko) 2010-12-17
WO2010035957A2 (ko) 2010-04-01
KR20100035045A (ko) 2010-04-02

Similar Documents

Publication Publication Date Title
AU2009286432B2 (en) Heuristic method of code analysis
WO2009014779A3 (en) System for malware normalization and detection
JP2009543186A5 (ko)
JP5265061B1 (ja) 悪意のあるファイル検査装置及び方法
GB2467685A (en) Risk scoring system for the prevention of malware
WO2004097604A3 (en) A method of, and system for, heuristically detective viruses in executable code
GB2478098A (en) System and method for run-time attack prevention
WO2011050089A3 (en) Preventing and responding to disabling of malware protection software
WO2006078446A3 (en) Intrusion detection system
MX2007011685A (es) Proteccion de una computadora que proporciona un servicio web de programa maligno.
WO2007125422A3 (en) System and method for enforcing a security context on a downloadable
WO2011084614A3 (en) Obfuscated malware detection
WO2014012106A3 (en) Retroactively detecting malicious or undesirable software
WO2007117582A3 (en) Malware detection system and method for mobile platforms
EP2790122A3 (en) System and method for correcting antivirus records to minimize false malware detections
WO2007124416A3 (en) Backwards researching activity indicative of pestware
WO2007094942A3 (en) Dynamic threat event management system and method
WO2010025007A3 (en) Protecting a virtual guest machine from attacks by an infected host
WO2004097602A3 (en) A method of, and system for, heuristically determining that an unknown file is harmless by using traffic heuristics
WO2007022392A3 (en) Information protection method and system
WO2010024606A3 (ko) 정상 파일 데이터베이스 제공 시스템 및 방법
WO2011127488A3 (en) Systems and methods of processing data associated with detection and/or handling of malware
CN102984134B (zh) 安全防御系统
CN102984135B (zh) 安全防御方法、装置与系统
WO2010035957A3 (ko) 은폐된 시스템 개체 진단 시스템 및 진단 방법

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09816350

Country of ref document: EP

Kind code of ref document: A2

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 09816350

Country of ref document: EP

Kind code of ref document: A2