Apparatus and method for detecting obfuscated malicious web page
    21.
    发明授权
    Apparatus and method for detecting obfuscated malicious web page 有权
    用于检测混淆的恶意网页的装置和方法

    公开(公告)号:US08424090B2

    公开(公告)日:2013-04-16

    申请号:US12410636

    申请日:2009-03-25

    CPC classification number: G06F21/53 G06F21/563 H04L63/1466

    Abstract: An apparatus and method for detecting an obfuscated malicious web page are provided to find a malicious web page by deobfuscating an obfuscated malicious code. The apparatus includes an obfuscated code detector that detects whether an obfuscated code is included in a source code of a web page, a deobfuscation function inserter that reconfigures the source code by inserting a function for deobfuscating the obfuscated code into the source code, a deobfuscator that is called by the function inserted into the reconfigured source code and deobfuscates the obfuscated code, and a malicious code detector that detects a malicious code using the deobfuscated code.

    Abstract translation: 提供用于检测混淆的恶意网页的装置和方法,以通过对模糊的恶意代码进行混淆来查找恶意网页。 该装置包括:检测网页的源代码中是否包含混淆的代码的混淆代码检测器;通过插入用于将模糊化代码混淆到源代码中的功能来重新配置源代码的去模糊功能插入器;解扰器, 被插入到重新配置的源代码中的功能调用,并且对混淆的代码进行混淆,以及使用去模糊化代码来检测恶意代码的恶意代码检测器。

    METHOD AND APPARATUS FOR DIGITAL FORENSICS
    23.
    发明申请
    METHOD AND APPARATUS FOR DIGITAL FORENSICS 有权
    数字法人的方法与装置

    公开(公告)号:US20090299935A1

    公开(公告)日:2009-12-03

    申请号:US12252869

    申请日:2008-10-16

    CPC classification number: G06K9/00

    Abstract: A method and apparatus for digital forensics are provided. The apparatus for digital forensics includes a page file extractor for extracting a page file stored in a target storage medium, a stored-page feature extractor for extracting features of pages stored in the extracted page file, a page classifier for comparing the extracted features of the pages with at least one predetermined classification criterion and classifying the pages according to the comparison results, and a digital forensics unit for performing digital forensics according to the classified pages. According to the method and apparatus, it is possible to perform digital forensics using only information of a page file.

    Abstract translation: 提供了一种用于数字取证的方法和装置。 用于数字取证的装置包括用于提取存储在目标存储介质中的页面文件的页面文件提取器,用于提取存储在所提取的页面文件中的页面的特征的存储页面特征提取器,用于将提取的特征提取的页面分类器 具有至少一个预定分类标准的页面,并根据比较结果分类页面;以及数字取证单元,用于根据分类页面进行数字取证。 根据该方法和装置,可以仅使用页面文件的信息来执行数字取证。

    APPARATUS AND METHOD FOR MONITORING AND PROTECTING SYSTEM RESOURCES FROM WEB BROWSER
    24.
    发明申请
    APPARATUS AND METHOD FOR MONITORING AND PROTECTING SYSTEM RESOURCES FROM WEB BROWSER 有权
    用于从网络浏览器监控和保护系统资源的装置和方法

    公开(公告)号:US20090100517A1

    公开(公告)日:2009-04-16

    申请号:US12208401

    申请日:2008-09-11

    CPC classification number: G06F21/554 G06F21/629 G06F2221/2141 H04L63/10

    Abstract: An apparatus and method for preventing an attempt to perform malicious activities using web browser weaknesses are provided. A file protection module monitors attempts to access at least one file resource when the web browser executes a program, and allows or denies access. A registry protection module monitors attempts to access at least one registry resource when the web browser executes a program, and allows or denies access. A process protection module monitors attempts to execute or terminate at least one process when the web browser executes a program, and allows or denies the execution or termination.

    Abstract translation: 提供了一种用于防止尝试使用web浏览器弱点进行恶意活动的装置和方法。 当Web浏览器执行程序并允许或拒绝访问时,文件保护模块监视尝试访问至少一个文件资源。 注册表保护模块监视在Web浏览器执行程序时访问至少一个注册表资源的尝试,并允许或拒绝访问。 当Web浏览器执行程序时,进程保护模块监视执行或终止至少一个进程的尝试,并允许或拒绝执行或终止。

    METHOD AND APPARATUS FOR ANALYZING EXPLOIT CODE IN NONEXECUTABLE FILE USING VIRTUAL ENVIRONMENT
    25.
    发明申请
    METHOD AND APPARATUS FOR ANALYZING EXPLOIT CODE IN NONEXECUTABLE FILE USING VIRTUAL ENVIRONMENT 审中-公开
    使用虚拟环境分析不可转让文件中的开发代码的方法和装置

    公开(公告)号:US20090094585A1

    公开(公告)日:2009-04-09

    申请号:US12056434

    申请日:2008-03-27

    CPC classification number: G06F9/455 G06F21/566

    Abstract: Provided is a method and apparatus for analyzing an exploit code included in a nonexecutable file using a target program with vulnerability in a virtual environment. The method includes the steps of: loading a nonexecutable file including the exploit code by a target program, the target program being executed in a virtual environment and includes vulnerability; analyzing a register value of the target program and determining if the register value of the target program indicates a normal code region; storing log information on operation of the target program when the register value indicates a region other than the normal code region; and extracting and analyzing the exploit code included in the nonexecutable file based on the stored log information. In this method, the exploit code is analyzed in the virtual environment, thereby preventing damage caused by execution of the exploit code.

    Abstract translation: 提供了一种用于使用在虚拟环境中具有脆弱性的目标程序来分析包含在不可执行文件中的利用代码的方法和装置。 该方法包括以下步骤:通过目标程序加载包括漏洞利用码的不可执行文件,目标程序在虚拟环境中执行,并且包括漏洞; 分析目标程序的寄存器值,并确定目标程序的寄存器值是否指示正常代码区; 当所述寄存器值指示除了所述正常代码区域之外的区域时,存储关于所述目标程序的操作的日志信息; 并且基于存储的日志信息提取和分析包括在不可执行文件中的利用代码。 在这种方法中,在虚拟环境中分析漏洞代码,从而防止由执行漏洞利用代码造成的损害。

    COSMETIC CONTAINER PROVIDED WITH PUMP INCLUDING PART MADE OF POLYKETONE MATERIAL

    公开(公告)号:US20210161274A1

    公开(公告)日:2021-06-03

    申请号:US16954074

    申请日:2018-10-29

    Applicant: Do Hoon LEE

    Inventor: Do Hoon LEE

    Abstract: The present invention relates to a cosmetic container provided with a pump including a part made of a polyketone material, wherein the pump functions to pump a cosmetic to the outside and has some part made of the eco-friendly material polyketone, whereby the problems of odor generation and harmfulness of formaldehyde, which is a raw material for the conventional substance polyacetal (polyoxymethylene (POM)), can be eliminated to give the user neither an unpleasant feeling nor irritation, thus allowing the user to use the cosmetic safely.

    Apparatus and method for preventing anomaly of application program
    27.
    发明授权
    Apparatus and method for preventing anomaly of application program 有权
    防止应用程序异常的装置和方法

    公开(公告)号:US08621624B2

    公开(公告)日:2013-12-31

    申请号:US12332012

    申请日:2008-12-10

    CPC classification number: G06F21/554 G06F21/52

    Abstract: An apparatus and method for preventing an anomaly of an application program are provided. More particularly, an apparatus and method for preventing an anomaly of an application program that detect and stop an anomaly on the basis of a behavior profile for an application program are provided. The apparatus includes a behavior monitor that detects behavior of an application program in operation, an anomaly detector that determines whether the detected behavior of the application program is an anomaly on the basis of a behavior profile of the application program in operation, and an anomaly stopper that stops the behavior of the application program determined as an anomaly by the anomaly detector. Possible application program behavior is stored according to its purpose in a behavior profile and an anomaly is detected and stopped on the basis of the behavior profile, thereby decreasing a false-positive rate of anomaly detection and simultaneously solving a problem of a conventional security programs being incapable of defending against attacks using the authority of a program trusted by a user.

    Abstract translation: 提供一种用于防止应用程序的异常的装置和方法。 更具体地,提供一种用于防止基于应用程序的行为特征来检测和停止异常的应用程序的异常的装置和方法。 该装置包括:行为监视器,其检测运行中的应用程序的行为;异常检测器,其基于运行中的应用程序的行为特征来确定检测到的应用程序的行为是否为异常;异常阻塞 这阻止由异常检测器确定为异常的应用程序的行为。 可能的应用程序行为根据其目的存储在行为配置文件中,并且基于行为配置文件检测和停止异常,从而减少异常检测的假阳性率并同时解决常规安全程序的问题 不能使用用户信任的程序的权限来防御攻击。

    APPARATUS FOR DETECTING PARTIAL DISCHARGE SIGNAL AND METHOD THEREOF
    28.
    发明申请
    APPARATUS FOR DETECTING PARTIAL DISCHARGE SIGNAL AND METHOD THEREOF 审中-公开
    用于检测部分放电信号的装置及其方法

    公开(公告)号:US20120235688A1

    公开(公告)日:2012-09-20

    申请号:US13420463

    申请日:2012-03-14

    Applicant: Do Hoon LEE

    Inventor: Do Hoon LEE

    CPC classification number: G01R31/1227

    Abstract: An apparatus for detecting a partial discharge (PD) signal capable of detecting a PD signal of a power device includes: a partial discharge (PD) coupler connected to a ground side of a power device and configured to cancel a low frequency noise component including a commercial frequency from an AC component flowing through the ground side of the power device when a partial PD signal is generated from the power device, and to allow a high frequency component including a PD signal included in the AC component to pass therethrough to generate a PD analog signal; and a PD detection unit configured to cancel a noise signal from the PD analog signal generated by the PD coupler to detect only the PD signal.

    Abstract translation: 用于检测能够检测功率器件的PD信号的局部放电(PD)信号的装置包括:连接到功率器件的接地侧的局部放电(PD)耦合器,并且被配置为抵消包括 当从功率器件产生部分PD信号时,流过电力设备的接地侧的AC组件的商业频率,并且允许包括AC组件中包括的PD信号的高频分量通过其中以产生PD 模拟信号; 以及PD检测单元,被配置为从PD耦合器产生的PD模拟信号中消除噪声信号,以仅检测PD信号。

    Furan-Based Curable Compound Derived from Biomass, Solvent-Free Curable Composition, and Method for Preparing Same
    29.
    发明申请
    Furan-Based Curable Compound Derived from Biomass, Solvent-Free Curable Composition, and Method for Preparing Same 有权
    来自生物质的呋喃类固化剂,无溶剂固化性组合物及其制备方法

    公开(公告)号:US20120220742A1

    公开(公告)日:2012-08-30

    申请号:US13394910

    申请日:2010-05-11

    CPC classification number: C07D407/14 C08F2/48 C08G59/26

    Abstract: The present invention relates to a furan-based curable compound derived from carbohydrate-based biomass, to a solvent-free curable composition, and to a method for preparing thereof, wherein the furan-based curable compound derived from biomass according to the present invention includes two epoxide functional groups bonded to at least one furan-based compound. The present invention may provide an environmentally friendly next-generation curable compound comprising a novel furan-based compound derived from biomass, which may be substituted for curable materials derived from oil resources, as a basic backbone, as well as a composition containing the same. According to the present invention, a curable material, which has a low contraction ratio during curing as compared to conventional radical-type curing materials, may be obtained, and a compound applied to the novel curing material may be prepared with a combination of excellent efficiency and cost-effectiveness.

    Abstract translation: 本发明涉及一种衍生自碳水化合物的生物质的呋喃类固化性化合物,无溶剂的可固化组合物及其制备方法,其中衍生自本发明的生物质的呋喃类固化性化合物包括 两个与至少一种呋喃基化合物键合的环氧官能团。 本发明可以提供一种环保的下一代可固化化合物,其包含衍生自生物质的新型呋喃基化合物,其可以替代源自石油资源的可固化材料作为基本骨架,以及含有该衍生物的组合物。 根据本发明,可以获得与常规自由基固化材料相比在固化期间具有低收缩率的可固化材料,并且可以以优异的效率组合来制备应用于新型固化材料的化合物 和成本效益。

    System and method for predicting cyber threat
    30.
    发明授权
    System and method for predicting cyber threat 有权
    用于预测网络威胁的系统和方法

    公开(公告)号:US08191149B2

    公开(公告)日:2012-05-29

    申请号:US11938356

    申请日:2007-11-12

    CPC classification number: H04L63/145 G06F21/552

    Abstract: Provided are a system and method for predicting a cyber threat. The system and method collect various variables and synthetically predict the frequency, dangerousness, possibility, and time of the occurrence of a cyber threat including hacking, a worm/virus, a Denial of Service (DoS) attack, illegal system access, a malicious code, a social engineering attack, system/data falsification, cyber terror/war, weakness exploitation, etc., using a time-series analysis method and a Delphi method, and inform a user in advance of the prediction result, thereby enabling the user to prepare against the cyber threat.

    Abstract translation: 提供了一种用于预测网络威胁的系统和方法。 系统和方法收集各种变量,综合预测网络威胁发生的频率,危险性,可能性和时间,包括黑客,蠕虫/病毒,拒绝服务(DoS)攻击,非法系统访问,恶意代码 使用时间序列分析方法和德尔菲法进行社会工程攻击,系统/数据伪造,网络恐怖/战争,弱势利用等,并提前通知用户预测结果,从而使用户能够 准备反对网络威胁。

Patent Agency Ranking