发明授权
US07996904B1 Automated unpacking of executables packed by multiple layers of arbitrary packers
有权
自动打包由多层任意打包机打包的可执行文件
- 专利标题: Automated unpacking of executables packed by multiple layers of arbitrary packers
- 专利标题(中): 自动打包由多层任意打包机打包的可执行文件
-
申请号: US11960426申请日: 2007-12-19
-
公开(公告)号: US07996904B1公开(公告)日: 2011-08-09
- 发明人: Tzi-cker Chiueh , Fanglu Guo
- 申请人: Tzi-cker Chiueh , Fanglu Guo
- 申请人地址: US CA Mountain View
- 专利权人: Symantec Corporation
- 当前专利权人: Symantec Corporation
- 当前专利权人地址: US CA Mountain View
- 代理机构: Fenwick & West LLP
- 主分类号: G06F11/00
- IPC分类号: G06F11/00
摘要:
The packing manager provides an automated method that allows existing AV scanning technology to be applied to detect known malware samples packed by one or more packers that are potentially proprietary. The packing manager tracks the memory areas to which an executable binary writes and executes, and so can unpack programs packed by multiple arbitrary packers without requiring reverse-engineering of the packers or any human intervention. By tracking page modification and execution of an executable binary at run time, the packing control module can detect the instant at which the program's control is first transferred to a page whose content is dynamically generated, so AV scanning can then be invoked. Thus, code cannot be executed under the packing control manager without being scanned by an AV scanner first.
公开/授权文献
- US1832326A Direction indicating device 公开/授权日:1931-11-17
信息查询