发明授权
- 专利标题: Method, system, and apparatus for detecting malicious code
- 专利标题(中): 用于检测恶意代码的方法,系统和设备
-
申请号: US14162139申请日: 2014-01-23
-
公开(公告)号: US09465941B2公开(公告)日: 2016-10-11
- 发明人: Peng Wang , Peng Yun
- 申请人: Huawei Technologies Co., Ltd.
- 申请人地址: CN Shenzhen
- 专利权人: HUAWEI TECHNOLOGIES CO., LTD.
- 当前专利权人: HUAWEI TECHNOLOGIES CO., LTD.
- 当前专利权人地址: CN Shenzhen
- 代理机构: Huawei Technologies Co., Ltd.
- 优先权: CN201110226659 20110809
- 主分类号: G06F21/53
- IPC分类号: G06F21/53 ; G06F21/56
摘要:
A method, a system, and an apparatus for detecting malicious code to solve the problem that detection efficiency is low and that more resources are occupied. The method includes: monitoring execution of an instruction in a virtual machine supervisor of a host computer, where the instruction is generated in escape mode when a read-write request generated during execution of program code in a virtual machine of the host computer is delivered to the virtual machine supervisor; obtaining execution characteristics of the program code according to execution of the instruction; and comparing the obtained execution characteristics with pre-stored execution characteristics of known malicious code, and determining that the program code is malicious code when the obtained execution characteristics and the pre-stored execution characteristics are the same. This improves the detection efficiency, and saves the storage resources and the processing resources in the host computer.
公开/授权文献
信息查询