Virtual server and method for identifying zombie, and sinkhole server and method for integratedly managing zombie information
    1.
    发明授权
    Virtual server and method for identifying zombie, and sinkhole server and method for integratedly managing zombie information 有权
    用于识别僵尸的虚拟服务器和方法,以及用于综合管理僵尸信息的沉没服务器和方法

    公开(公告)号:US08706866B2

    公开(公告)日:2014-04-22

    申请号:US12985728

    申请日:2011-01-06

    IPC分类号: G06F21/20 G06F15/173

    摘要: Provided are a virtual server and method for identifying a zombie, and a sinkhole server and method for integratedly managing zombie information. The virtual server includes an authentication processing module authenticating a host using a CAPTCHA test and providing a cookie to the authenticated host when a web server access request message received from the host does not include a cookie, a cookie value verification module for extracting a cookie value from the web server access request message and verifying the extracted cookie value when the web server access request message includes a cookie, a web page access inducement module for inducing the host to access a web server when the cookie value is verified, and a zombie identification module for blocking access of the host when the cookie value is not verified, and identifying the host as a zombie when the number of blocking operations exceeds a threshold value.

    摘要翻译: 提供了用于识别僵尸的虚拟服务器和方法,以及用于综合管理僵尸信息的宿窝服务器和方法。 虚拟服务器包括认证处理模块,使用CAPTCHA测试认证主机,并且当从主机接收到的web服务器访问请求消息不包括cookie时,向认证主机提供cookie,用于提取cookie值的cookie值验证模块 当web服务器访问请求消息包括cookie时,从Web服务器访问请求消息和验证提取的cookie值,当cookie值被验证时用于诱导主机访问web服务器的网页访问诱导模块,以及僵尸识别 当cookie值未被验证时阻止主机访问的模块,以及当阻塞操作次数超过阈值时将主机识别为僵尸。

    APPARATUS, SYSTEM AND METHOD FOR DETECTING MALICIOUS CODE
    4.
    发明申请
    APPARATUS, SYSTEM AND METHOD FOR DETECTING MALICIOUS CODE 有权
    用于检测恶意代码的装置,系统和方法

    公开(公告)号:US20110271343A1

    公开(公告)日:2011-11-03

    申请号:US12985252

    申请日:2011-01-05

    IPC分类号: G06F21/00

    CPC分类号: G06F21/566

    摘要: Provided are an apparatus, system and method for detecting malicious code inserted into a normal process in disguise. The apparatus includes a malicious code detection module for extracting information on a thread generated by a process running on a computer system to identify code related to the thread, preliminarily determining whether or not the identified code is malicious and extracting the code preliminarily determined to be malicious; and a forcible malicious code termination module for finally determining the code as malicious code based on an analysis result of behavior of the extracted code executed in a virtual environment and forcibly terminating execution of the code.

    摘要翻译: 提供了一种用于检测插入到伪装的正常进程中的恶意代码的装置,系统和方法。 该装置包括恶意代码检测模块,用于提取由计算机系统上运行的进程生成的线程的信息,以识别与该线程相关的代码,初步确定所识别的代码是否是恶意的,并提取初步确定为恶意的代码 ; 以及强制恶意代码终止模块,用于基于在虚拟环境中执行的提取的代码的行为的分析结果,最终将代码确定为恶意代码,并强制终止代码的执行。

    VIRTUAL SERVER AND METHOD FOR IDENTIFYING ZOMBIE, AND SINKHOLE SERVER AND METHOD FOR INTEGRATEDLY MANAGING ZOMBIE INFORMATION
    5.
    发明申请
    VIRTUAL SERVER AND METHOD FOR IDENTIFYING ZOMBIE, AND SINKHOLE SERVER AND METHOD FOR INTEGRATEDLY MANAGING ZOMBIE INFORMATION 有权
    用于识别ZOMBIE的虚拟服务器和方法,以及用于集成管理ZOMBIE信息的SINKHOVER服务器和方法

    公开(公告)号:US20110270969A1

    公开(公告)日:2011-11-03

    申请号:US12985728

    申请日:2011-01-06

    IPC分类号: G06F21/20 G06F15/173

    摘要: Provided are a virtual server and method for identifying a zombie, and a sinkhole server and method for integratedly managing zombie information. The virtual server includes an authentication processing module authenticating a host using a CAPTCHA test and providing a cookie to the authenticated host when a web server access request message received from the host does not include a cookie, a cookie value verification module for extracting a cookie value from the web server access request message and verifying the extracted cookie value when the web server access request message includes a cookie, a web page access inducement module for inducing the host to access a web server when the cookie value is verified, and a zombie identification module for blocking access of the host when the cookie value is not verified, and identifying the host as a zombie when the number of blocking operations exceeds a threshold value.

    摘要翻译: 提供了用于识别僵尸的虚拟服务器和方法,以及用于综合管理僵尸信息的宿窝服务器和方法。 虚拟服务器包括认证处理模块,使用CAPTCHA测试认证主机,并且当从主机接收到的web服务器访问请求消息不包括cookie时,向认证主机提供cookie,用于提取cookie值的cookie值验证模块 当web服务器访问请求消息包括cookie时,从Web服务器访问请求消息和验证提取的cookie值,当cookie值被验证时用于诱导主机访问web服务器的网页访问诱导模块,以及僵尸识别 当cookie值未被验证时阻止主机访问的模块,以及当阻塞操作次数超过阈值时将主机识别为僵尸。

    Apparatus, system and method for detecting malicious code
    6.
    发明授权
    Apparatus, system and method for detecting malicious code 有权
    用于检测恶意代码的装置,系统和方法

    公开(公告)号:US08955124B2

    公开(公告)日:2015-02-10

    申请号:US12985252

    申请日:2011-01-05

    IPC分类号: G06F21/00 G06F21/56

    CPC分类号: G06F21/566

    摘要: Provided are an apparatus, system and method for detecting malicious code inserted into a normal process in disguise. The apparatus includes a malicious code detection module for extracting information on a thread generated by a process running on a computer system to identify code related to the thread, preliminarily determining whether or not the identified code is malicious and extracting the code preliminarily determined to be malicious; and a forcible malicious code termination module for finally determining the code as malicious code based on an analysis result of behavior of the extracted code executed in a virtual environment and forcibly terminating execution of the code.

    摘要翻译: 提供了一种用于检测插入到伪装的正常进程中的恶意代码的装置,系统和方法。 该装置包括恶意代码检测模块,用于提取由计算机系统上运行的进程生成的线程的信息,以识别与该线程相关的代码,初步确定所识别的代码是否是恶意的,并提取初步确定为恶意的代码 ; 以及强制恶意代码终止模块,用于基于在虚拟环境中执行的提取的代码的行为的分析结果,最终将代码确定为恶意代码,并强制终止代码的执行。