发明授权
- 专利标题: Document exploit detection using baseline comparison
- 专利标题(中): 使用基准比较的文档利用检测
-
申请号: US13794400申请日: 2013-03-11
-
公开(公告)号: US09239922B1公开(公告)日: 2016-01-19
- 发明人: Xuewen Zhu , Xinfeng Liu , Xuebin Chen , Qiang Huang
- 申请人: Xuewen Zhu , Xinfeng Liu , Xuebin Chen , Qiang Huang
- 申请人地址: JP Tokyo
- 专利权人: Trend Micro Inc.
- 当前专利权人: Trend Micro Inc.
- 当前专利权人地址: JP Tokyo
- 代理机构: Beyer Law Group LLP
- 主分类号: G06F21/56
- IPC分类号: G06F21/56 ; G06F21/55
摘要:
An application document known to include malware (such as a document exploit) is opened and executed by its corresponding software application. Behaviors of this document (such as registry, file system, network and process) are monitored and recorded using internal software drivers and hook modules. A behavior report is generated and a baseline pattern is created including a number of regular expressions. A suspicious document of the same type as the monitored document is opened and executed by the same corresponding software application. Behaviors are monitored in the same way and a behavior report is generated. This behavior report is compared to the baseline pattern and a determination is made as to whether a document exploit is present. Known benign documents may also be opened, monitored and their behavior recorded, resulting in creation of a known benign pattern for the corresponding software application.
信息查询