DETECTION SYSTEM AND METHOD OF SUSPICIOUS MALICIOUS WEBSITE USING ANALYSIS OF JAVASCRIPT OBFUSCATION STRENGTH
    1.
    发明申请
    DETECTION SYSTEM AND METHOD OF SUSPICIOUS MALICIOUS WEBSITE USING ANALYSIS OF JAVASCRIPT OBFUSCATION STRENGTH 有权
    使用JAVASCRIPT OBFUSCING强度分析检测系统和可疑恶性网站的方法

    公开(公告)号:US20120159621A1

    公开(公告)日:2012-06-21

    申请号:US13282911

    申请日:2011-10-27

    IPC分类号: G06F21/00

    摘要: The present invention provides a detection system of a suspicious malicious website using the analysis of a JavaScript obfuscation strength, which includes: an entropy measuring block of measuring an entropy of an obfuscated JavaScript present in the website, a special character entropy, and a variable/function name entropy; a frequency measuring block of measuring a specific function frequency, an encoding mark frequency and a % symbol frequency of the JavaScript; a density measuring block of measuring the maximum length of a single character string of the JavaScript; and a malicious website confirming block of determining whether the relevant website is malicious by comparing an obfuscation strength value, measured by the entropy measuring block, the frequency measuring block and the density measuring block, with a threshold value.

    摘要翻译: 本发明提供了一种使用JavaScript混淆强度分析的可疑恶意网站的检测系统,其包括:测量网站中存在的模糊JavaScript的熵的熵测量块,特殊字符熵和可变/ 函数名熵 测量特定功能频率的频率测量块,JavaScript的编码标记频率和%符号频率; 测量JavaScript的单个字符串的最大长度的密度测量块; 以及通过将熵测量块测量的混淆强度值,频率测量块和密度测量块与阈值进行比较来确定相关网站是否是恶意的恶意网站确认块。

    Detection system and method of suspicious malicious website using analysis of javascript obfuscation strength
    2.
    发明授权
    Detection system and method of suspicious malicious website using analysis of javascript obfuscation strength 有权
    使用javascript混淆强度分析的可疑恶意网站的检测系统和方法

    公开(公告)号:US08756685B2

    公开(公告)日:2014-06-17

    申请号:US13282911

    申请日:2011-10-27

    IPC分类号: G06F21/00 G06F21/51

    摘要: A detection system of a suspicious malicious website using the analysis of a JavaScript obfuscation strength, which includes: an entropy measuring processor of measuring an entropy of an obfuscated JavaScript present in the website, a special character entropy, and a variable/function name entropy; a frequency measuring processor of measuring a specific function frequency, an encoding mark frequency and a % symbol frequency of the JavaScript; a density measuring processor of measuring the maximum length of a single character string of the JavaScript; and a malicious website confirming processor of determining whether the relevant website is malicious by comparing an obfuscation strength value, measured by the entropy measuring processor, the frequency measuring processor and the density measuring processor, with a threshold value.

    摘要翻译: 一种使用JavaScript混淆强度分析的可疑恶意网站的检测系统,其包括:测量网站中存在的模糊JavaScript的熵的熵测量处理器,特殊字符熵和可变/函数名称熵; 测量JavaScript的特定功能频率,编码标记频率和%符号频率的频率测量处理器; 测量JavaScript的单个字符串的最大长度的密度测量处理器; 以及通过将由熵测量处理器,频率测量处理器和密度测量处理器测量的混淆强度值与阈值进行比较来确定相关网站是否是恶意的恶意网站确认处理器。

    SEED INFORMATION COLLECTING DEVICE AND METHOD FOR DETECTING MALICIOUS CODE LANDING/HOPPING/DISTRIBUTION SITES
    3.
    发明申请
    SEED INFORMATION COLLECTING DEVICE AND METHOD FOR DETECTING MALICIOUS CODE LANDING/HOPPING/DISTRIBUTION SITES 审中-公开
    收集信息的收集信息和检测恶意代码登陆/篡改/分发站点的方法

    公开(公告)号:US20120167220A1

    公开(公告)日:2012-06-28

    申请号:US13304986

    申请日:2011-11-28

    IPC分类号: G06F11/00

    CPC分类号: G06F21/563

    摘要: Provided is seed information collecting device for detecting malicious code landing/hopping/distribution sites. The device comprises: a seed information collecting module collecting social issue keywords from a seed information collecting channel and collecting address information of potential malicious code landing/hopping/distribution sites using the collected social issue keywords; a web source code collecting module collecting web source code of the potential malicious code landing/hopping/distribution sites using the address information of the potential malicious code landing/hopping/distribution sites collected by the seed information collecting module; and a policy management module managing collection policies of the seed information collecting module and the web source code collecting module.

    摘要翻译: 提供了用于检测恶意代码登陆/跳跃/分发站点的种子信息收集装置。 该装置包括:种子信息收集模块,从种子信息采集通道收集社会问题关键词,并使用所收集的社会问题关键词收集潜在的恶意代码登陆/跳出/分发站点的地址信息; 网站源代码收集模块,利用种子信息收集模块收集的潜在恶意代码登陆/跳跃/分发站点的地址信息,收集潜在恶意代码登陆/分发站点的网站源代码; 以及策略管理模块,其管理种子信息收集模块和web源代码收集模块的收集策略。

    AUTOMATIC MANAGEMENT SYSTEM FOR GROUP AND MUTANT INFORMATION OF MALICIOUS CODES
    4.
    发明申请
    AUTOMATIC MANAGEMENT SYSTEM FOR GROUP AND MUTANT INFORMATION OF MALICIOUS CODES 审中-公开
    自动管理系统,用于组合和错误信息的恶意代码

    公开(公告)号:US20120311709A1

    公开(公告)日:2012-12-06

    申请号:US13304981

    申请日:2011-11-28

    IPC分类号: G06F21/00

    CPC分类号: G06F21/56 G06F8/75

    摘要: An automatic management system includes a malicious code group-mutant storage module that receives a malicious codes analysis result from a malicious code collection-analysis system and extracts group information and mutant information of the malicious codes based on the malicious code analysis result, a malicious code group-mutant DB that stores the extracted group information and mutant information, a malicious code group-mutant management module that provides interface to allow a user to detect the group information and mutant information stored in the malicious code group-mutant DB, and a visualizing module that outputs the detection result to the user, wherein the malicious code group-mutant management module that groups malicious codes having action associations using the group information and mutant information stored in the malicious code group-mutant DB, outputs the group information through the visualizing module and outputs the mutant information based on CFG similarity and string similarity through the visualizing module.

    摘要翻译: 自动管理系统包括恶意代码组 - 突变存储模块,其从恶意代码收集分析系统接收恶意代码分析结果,并基于恶意代码分析结果提取恶意代码的组信息和突变信息,恶意代码 存储提取的组信息和突变体信息的组突变体DB,恶意代码组突变体管理模块,其提供接口以允许用户检测存储在恶意代码组突变体DB中的组信息和突变信息,以及可视化 向用户输出检测结果的模块,其中,使用存储在恶意代码组突变体DB中的组信息和突变信息分组具有动作关联的恶意代码的恶意代码组突变体管理模块通过可视化输出组信息 模块并输出基于CFG相似度的突变信息 通过可视化模块进行字符串相似。

    SYSTEM AND METHOD FOR BLOCKING SIP-BASED ABNORMAL TRAFFIC
    6.
    发明申请
    SYSTEM AND METHOD FOR BLOCKING SIP-BASED ABNORMAL TRAFFIC 审中-公开
    用于阻塞基于SIP的异常交通的系统和方法

    公开(公告)号:US20120060218A1

    公开(公告)日:2012-03-08

    申请号:US12943388

    申请日:2010-11-10

    IPC分类号: G06F11/00

    摘要: Provided is a system for blocking session initiation protocol (SIP)-based abnormal traffic. The system includes: a policy database (DB) in which allowed traffic is stored according to transmission priority; an abnormal traffic response module which receives traffic from a first network and transmits only portions of the received traffic, which match the allowed traffic stored in the policy DB, to a second network in order of transmission priority; and an abnormal traffic detection module which analyzes the traffic received from the first network and provides an activation signal to the abnormal traffic response module when detecting that the received traffic is abnormal traffic, wherein the abnormal traffic response module transmits the portions of the received traffic, which match the allowed traffic stored in the policy DB, to the second network such that the sum of the portions transmitted to the second network does not exceed a maximum allowed traffic limit.

    摘要翻译: 提供了一种用于阻止基于会话发起协议(SIP)的异常流量的系统。 该系统包括:策略数据库(DB),其中根据传输优先级存储允许的流量; 异常业务响应模块,其从第一网络接收业务,并且仅将与策略DB中存储的允许业务相匹配的所接收到的业务的部分按照传输优先级顺序发送到第二网络; 以及异常流量检测模块,其分析从第一网络接收到的流量,并且当检测到所接收到的流量是异常流量时,向异常流量响应模块提供激活信号,其中异常流量响应模块发送所接收的流量的部分, 其将存储在策略DB中的允许的流量与第二网络匹配,使得发送到第二网络的部分的总和不超过允许的最大流量限制。

    ORGANIC LIGHT EMITTING DISPLAY DEVICE AND METHOD FOR MANUFACTURING THE SAME
    7.
    发明申请
    ORGANIC LIGHT EMITTING DISPLAY DEVICE AND METHOD FOR MANUFACTURING THE SAME 有权
    有机发光显示装置及其制造方法

    公开(公告)号:US20100155760A1

    公开(公告)日:2010-06-24

    申请号:US12643441

    申请日:2009-12-21

    IPC分类号: H01L51/52 H01L51/56

    摘要: Disclosed are an organic light emitting display device with improved yield and processing efficiency, which includes an interlayer capable of being separated into a hydrophilic region and a hydrophobic region on top of a hole injection layer in an organic light emitting device and a plurality of layers including a light emitting layer and which is fabricated without using a shadow mask, as well as a method for manufacturing the same. The manufacturing method includes preparing a substrate having a plurality of pixel regions defined in a matrix form, arranging an anode in each of the pixel regions, forming a hole injection layer on the anode by the solution process, forming an interlayer with hydrophobic properties on the hole injection layer by a solution process, selectively UV irradiating the interlayer to define a hydrophilic region on the interlayer, forming a light emitting layer on the interlayer by the solution process, and arranging a cathode on the substrate having the light emitting layer.

    摘要翻译: 公开了一种具有提高的产率和加工效率的有机发光显示装置,其包括能够分离成有机发光装置中的空穴注入层的顶部的亲水区域和疏水区域的层间,以及包括 在不使用荫罩的情况下制造发光层,以及其制造方法。 该制造方法包括制备具有以矩阵形式限定的多个像素区域的基板,在每个像素区域中布置阳极,通过溶液法在阳极上形成空穴注入层,在其上形成具有疏水性的中间层 通过溶液法选择性地UV照射中间层以在中间层上限定亲水区域,通过溶液法在中间层上形成发光层,并在具有发光层的基板上设置阴极。

    DEVICE AND METHOD FOR GENERATING STATISTICAL INFORMATION FOR VOIP TRAFFIC ANALYSIS AND ABNORMAL VOIP DETECTION
    9.
    发明申请
    DEVICE AND METHOD FOR GENERATING STATISTICAL INFORMATION FOR VOIP TRAFFIC ANALYSIS AND ABNORMAL VOIP DETECTION 有权
    用于生成用于VOIP交通分析和异常VOIP检测的统计信息的装置和方法

    公开(公告)号:US20110058481A1

    公开(公告)日:2011-03-10

    申请号:US12646290

    申请日:2009-12-23

    IPC分类号: H04L12/26

    CPC分类号: H04L43/026 H04L43/062

    摘要: A statistical information generator for VoIP traffic analysis is provided, which comprises a packet collection module collecting packets from a network; and a statistical information generation module analyzing information of a call setup packet or a media packet among the packets collected by the packet collection module, and generating statistical information of the network; wherein if the packet collected by the packet collection module is the call setup packet, the statistical information generation module generates the statistical information of the network using at least one of transmitter identification information, receiver identification information, and call identification information among information of the call setup packet as a key value, while if the packet collected by the packet collection module is the media packet, the statistical information generation module generates the statistical information of the network using media session identification information among information of the media packet as a key value.

    摘要翻译: 提供了一种用于VoIP流量分析的统计信息发生器,其包括从网络收集分组的分组收集模块; 以及统计信息生成模块,分析由所述分组收集模块收集的分组中的呼叫建立分组或媒体分组的信息,并生成所述网络的统计信息; 其中,如果由分组收集模块收集的分组是呼叫建立分组,则统计信息生成模块使用呼叫信息中的发射机识别信息,接收者识别信息和呼叫识别信息中的至少一个来生成网络的统计信息 设置分组为密钥值,而如果分组收集模块收集的分组是媒体分组,则统计信息生成模块使用媒体分组的信息之间的媒体会话识别信息作为关键值生成网络的统计信息。