- 专利标题: Method and apparatus for detecting shellcode
-
申请号: US11332115申请日: 2006-01-12
-
公开(公告)号: US08051479B1公开(公告)日: 2011-11-01
- 发明人: Zheng Bu , Fengmin Gong
- 申请人: Zheng Bu , Fengmin Gong
- 申请人地址: US CA Santa Clara
- 专利权人: McAfee, Inc.
- 当前专利权人: McAfee, Inc.
- 当前专利权人地址: US CA Santa Clara
- 代理机构: Wong, Cabello, Lutsch, Rutherford & Brucculeri, L.L.P.
- 主分类号: G06F12/14
- IPC分类号: G06F12/14 ; G06F12/16 ; G08B23/00
摘要:
The invention is a method and apparatus for detecting shellcode such that a set of computer instructions is scanned for the presence of a null operation instruction. The computer instructions are also examined for the presence of a system call instruction, and reviewed for the presence of a decoder instruction set. A null operation weight value is then determined corresponding to the null operation instruction. Also assessed is a system call weight value corresponding to the system call instruction. In addition, a decoder weight value is calculated corresponding to the decoder instruction set. The null operation weight value, the system call weight value, and the decoder weight value are then analyzed to identify a shellcode.
信息查询