APPARATUS AND METHOD FOR DETECTING MALWARE CODE BY GENERATING AND ANALYZING BEHAVIOR PATTERN

    公开(公告)号:US20170270299A1

    公开(公告)日:2017-09-21

    申请号:US15240319

    申请日:2016-08-18

    CPC classification number: G06F21/566 G06N5/022

    Abstract: The present invention relates to an apparatus and a method for detecting a malware code by generating and analyzing behavior pattern. A malware code detecting apparatus includes a behavior pattern generating unit which defines a characteristic parameter which distinguishes and specifies behaviors of a malware code and normally executable programs, converts an API calling event corresponding to the defined characteristic parameter and generates a behavior pattern in accordance with a similarity for behaviors of converted API call sequences to store the behavior pattern in a behavior pattern DB; and a malware code detecting unit which converts the API calling event corresponding to the defined characteristic parameter when the target process is executed into the API call sequence and determines whether the behavior pattern is a malware code in accordance with a similarity for behaviors of the converted API call sequence and the sequence stored in the behavior pattern DB.

    APPARATUS AND METHOD FOR DETECTING ABNORMAL BEHAVIOR
    6.
    发明申请
    APPARATUS AND METHOD FOR DETECTING ABNORMAL BEHAVIOR 审中-公开
    检测异常行为的装置和方法

    公开(公告)号:US20150199512A1

    公开(公告)日:2015-07-16

    申请号:US14248845

    申请日:2014-04-09

    Abstract: Provided are abnormal behavior detecting apparatus and method and the abnormal behavior detecting apparatus, includes: a behavior analyzing unit which analyzes a behavior which occurs for resources of a system based on data collected from a process while the process is executed on the system; a behavior modeling unit which models a behavior analysis result for the resources of the system on a coordinate which is generated based on the behavior for the resources of the system to create a process behavior model corresponding to the resources of the system; a suspicious behavior determining unit which determines a suspicious behavior of the process in accordance with the type of the process behavior model which is implemented on the coordinate; and a process detecting unit which detects a process in which the suspicious behavior occurs as an abnormal behavior process.

    Abstract translation: 提供了异常行为检测装置和方法以及异常行为检测装置,包括:行为分析单元,其基于在系统上执行处理时从进程收集的数据分析系统资源发生的行为; 行为建模单元,其基于系统的资源的行为生成的坐标来对系统的资源进行行为分析结果建模,以创建与系统的资源相对应的过程行为模型; 可疑行为确定单元,其根据在坐标上实现的过程行为模型的类型来确定过程的可疑行为; 以及处理检测单元,其检测作为异常行为处理发生可疑行为的处理。

Patent Agency Ranking