- 专利标题: Process analysis apparatus, process analysis method, and process analysis for determining input/output relation of a block of execution trace to detect potential malware
-
申请号: US15500476申请日: 2014-08-28
-
公开(公告)号: US10325094B2公开(公告)日: 2019-06-18
- 发明人: Takumi Yamamoto , Shoji Sakurai , Kiyoto Kawauchi
- 申请人: MITSUBISHI ELECTRIC CORPORATION
- 申请人地址: JP Tokyo
- 专利权人: MITSUBISHI ELECTRIC CORPORATION
- 当前专利权人: MITSUBISHI ELECTRIC CORPORATION
- 当前专利权人地址: JP Tokyo
- 代理机构: Birch, Stewart, Kolasch & Birch, LLP
- 国际申请: PCT/JP2014/004417 WO 20140828
- 国际公布: WO2016/030927 WO 20160303
- 主分类号: G06F21/00
- IPC分类号: G06F21/00 ; G06F21/56
摘要:
The present invention relates to a process analysis apparatus for analyzing a process executed in an information processing unit and extracting encryption logic such as an encryption function or a decryption function used in the process. The process analysis apparatus is provided with an execution trace acquisition section to acquire an execution trace of a process to be analyzed; a block extraction section to extract, from the execution trace, a block that is a processing unit indicating a loop structure; a block information extraction section to extract, from the block, block information including input information and output information; and a block information analysis section to generate characteristic determination information for determining a characteristic of an input/output relation of the block, using the input information or the output information of the block information, analyzing the input/output relation of the block, using the characteristic determination information, and determining the block which indicates a characteristic of an input/output relation of an encryption function or a decryption function, as the encryption logic.
公开/授权文献
信息查询