Cross-level data flow tracking method based on windows platform

The invention relates to a cross-level data flow tracking method based on a windows platform. The method includes the steps: acquiring API (application program interface) information for data exchangebetween a kernel state and a user state of a windows operation system; running a program to be analy...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: XIAO CHONGHUI, JIA ZIXIAO, YAO LI, ZHANG TENG, LI ZHIHUI, WANG XIAOQUN, MA LIYA, HAN ZHIHUI, ZHANG SHUAI, YAN HANBING, LEI JUN, GAO CHUAN, ZHOU YU, CHEN YANG, WANG SHIWEN, XU JIAN, LI JIA, DING LI, LYU ZHIQUAN, ZHU YUNQIAN, ZHOU HAO, WEN SENHAO
Format: Patent
Sprache:chi ; eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
container_end_page
container_issue
container_start_page
container_title
container_volume
creator XIAO CHONGHUI
JIA ZIXIAO
YAO LI
ZHANG TENG
LI ZHIHUI
WANG XIAOQUN
MA LIYA
HAN ZHIHUI
ZHANG SHUAI
YAN HANBING
LEI JUN
GAO CHUAN
ZHOU YU
CHEN YANG
WANG SHIWEN
XU JIAN
LI JIA
DING LI
LYU ZHIQUAN
ZHU YUNQIAN
ZHOU HAO
WEN SENHAO
description The invention relates to a cross-level data flow tracking method based on a windows platform. The method includes the steps: acquiring API (application program interface) information for data exchangebetween a kernel state and a user state of a windows operation system; running a program to be analyzed and executing an instruction of the program to be analyzed; traversing processes in the operation system and acquiring a process with the name consistent with that of a process of the program to be analyzed, and marking the process as a monitored process; marking data generated by executing themonitored process as monitored data of the user state; marking kernel data mapped after input as monitored data of the kernel state if corresponding input parameters are the monitored data of the user state in the API calling process of the program to be analyzed; tracking and analyzing data flow of the monitored data of the user state and the monitored data of the kernel state, and accordingly judging whether the program
format Patent
fullrecord <record><control><sourceid>epo_EVB</sourceid><recordid>TN_cdi_epo_espacenet_CN108229172A</recordid><sourceformat>XML</sourceformat><sourcesystem>PC</sourcesystem><sourcerecordid>CN108229172A</sourcerecordid><originalsourceid>FETCH-epo_espacenet_CN108229172A3</originalsourceid><addsrcrecordid>eNrjZLB3LsovLtbNSS1LzVFISSxJVEjLyS9XKClKTM7OzEtXyE0tychPUUhKLE5NUcjPUyjPzEvJLy9WKMhJLEnLL8rlYWBNS8wpTuWF0twMim6uIc4euqkF-fGpxQWJyal5qSXxzn6GBhZGRpaG5kaOxsSoAQCIfDDn</addsrcrecordid><sourcetype>Open Access Repository</sourcetype><iscdi>true</iscdi><recordtype>patent</recordtype></control><display><type>patent</type><title>Cross-level data flow tracking method based on windows platform</title><source>esp@cenet</source><creator>XIAO CHONGHUI ; JIA ZIXIAO ; YAO LI ; ZHANG TENG ; LI ZHIHUI ; WANG XIAOQUN ; MA LIYA ; HAN ZHIHUI ; ZHANG SHUAI ; YAN HANBING ; LEI JUN ; GAO CHUAN ; ZHOU YU ; CHEN YANG ; WANG SHIWEN ; XU JIAN ; LI JIA ; DING LI ; LYU ZHIQUAN ; ZHU YUNQIAN ; ZHOU HAO ; WEN SENHAO</creator><creatorcontrib>XIAO CHONGHUI ; JIA ZIXIAO ; YAO LI ; ZHANG TENG ; LI ZHIHUI ; WANG XIAOQUN ; MA LIYA ; HAN ZHIHUI ; ZHANG SHUAI ; YAN HANBING ; LEI JUN ; GAO CHUAN ; ZHOU YU ; CHEN YANG ; WANG SHIWEN ; XU JIAN ; LI JIA ; DING LI ; LYU ZHIQUAN ; ZHU YUNQIAN ; ZHOU HAO ; WEN SENHAO</creatorcontrib><description>The invention relates to a cross-level data flow tracking method based on a windows platform. The method includes the steps: acquiring API (application program interface) information for data exchangebetween a kernel state and a user state of a windows operation system; running a program to be analyzed and executing an instruction of the program to be analyzed; traversing processes in the operation system and acquiring a process with the name consistent with that of a process of the program to be analyzed, and marking the process as a monitored process; marking data generated by executing themonitored process as monitored data of the user state; marking kernel data mapped after input as monitored data of the kernel state if corresponding input parameters are the monitored data of the user state in the API calling process of the program to be analyzed; tracking and analyzing data flow of the monitored data of the user state and the monitored data of the kernel state, and accordingly judging whether the program</description><language>chi ; eng</language><subject>CALCULATING ; COMPUTING ; COUNTING ; ELECTRIC DIGITAL DATA PROCESSING ; PHYSICS</subject><creationdate>2018</creationdate><oa>free_for_read</oa><woscitedreferencessubscribed>false</woscitedreferencessubscribed></display><links><openurl>$$Topenurl_article</openurl><openurlfulltext>$$Topenurlfull_article</openurlfulltext><thumbnail>$$Tsyndetics_thumb_exl</thumbnail><linktohtml>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&amp;date=20180629&amp;DB=EPODOC&amp;CC=CN&amp;NR=108229172A$$EHTML$$P50$$Gepo$$Hfree_for_read</linktohtml><link.rule.ids>230,308,778,883,25547,76298</link.rule.ids><linktorsrc>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&amp;date=20180629&amp;DB=EPODOC&amp;CC=CN&amp;NR=108229172A$$EView_record_in_European_Patent_Office$$FView_record_in_$$GEuropean_Patent_Office$$Hfree_for_read</linktorsrc></links><search><creatorcontrib>XIAO CHONGHUI</creatorcontrib><creatorcontrib>JIA ZIXIAO</creatorcontrib><creatorcontrib>YAO LI</creatorcontrib><creatorcontrib>ZHANG TENG</creatorcontrib><creatorcontrib>LI ZHIHUI</creatorcontrib><creatorcontrib>WANG XIAOQUN</creatorcontrib><creatorcontrib>MA LIYA</creatorcontrib><creatorcontrib>HAN ZHIHUI</creatorcontrib><creatorcontrib>ZHANG SHUAI</creatorcontrib><creatorcontrib>YAN HANBING</creatorcontrib><creatorcontrib>LEI JUN</creatorcontrib><creatorcontrib>GAO CHUAN</creatorcontrib><creatorcontrib>ZHOU YU</creatorcontrib><creatorcontrib>CHEN YANG</creatorcontrib><creatorcontrib>WANG SHIWEN</creatorcontrib><creatorcontrib>XU JIAN</creatorcontrib><creatorcontrib>LI JIA</creatorcontrib><creatorcontrib>DING LI</creatorcontrib><creatorcontrib>LYU ZHIQUAN</creatorcontrib><creatorcontrib>ZHU YUNQIAN</creatorcontrib><creatorcontrib>ZHOU HAO</creatorcontrib><creatorcontrib>WEN SENHAO</creatorcontrib><title>Cross-level data flow tracking method based on windows platform</title><description>The invention relates to a cross-level data flow tracking method based on a windows platform. The method includes the steps: acquiring API (application program interface) information for data exchangebetween a kernel state and a user state of a windows operation system; running a program to be analyzed and executing an instruction of the program to be analyzed; traversing processes in the operation system and acquiring a process with the name consistent with that of a process of the program to be analyzed, and marking the process as a monitored process; marking data generated by executing themonitored process as monitored data of the user state; marking kernel data mapped after input as monitored data of the kernel state if corresponding input parameters are the monitored data of the user state in the API calling process of the program to be analyzed; tracking and analyzing data flow of the monitored data of the user state and the monitored data of the kernel state, and accordingly judging whether the program</description><subject>CALCULATING</subject><subject>COMPUTING</subject><subject>COUNTING</subject><subject>ELECTRIC DIGITAL DATA PROCESSING</subject><subject>PHYSICS</subject><fulltext>true</fulltext><rsrctype>patent</rsrctype><creationdate>2018</creationdate><recordtype>patent</recordtype><sourceid>EVB</sourceid><recordid>eNrjZLB3LsovLtbNSS1LzVFISSxJVEjLyS9XKClKTM7OzEtXyE0tychPUUhKLE5NUcjPUyjPzEvJLy9WKMhJLEnLL8rlYWBNS8wpTuWF0twMim6uIc4euqkF-fGpxQWJyal5qSXxzn6GBhZGRpaG5kaOxsSoAQCIfDDn</recordid><startdate>20180629</startdate><enddate>20180629</enddate><creator>XIAO CHONGHUI</creator><creator>JIA ZIXIAO</creator><creator>YAO LI</creator><creator>ZHANG TENG</creator><creator>LI ZHIHUI</creator><creator>WANG XIAOQUN</creator><creator>MA LIYA</creator><creator>HAN ZHIHUI</creator><creator>ZHANG SHUAI</creator><creator>YAN HANBING</creator><creator>LEI JUN</creator><creator>GAO CHUAN</creator><creator>ZHOU YU</creator><creator>CHEN YANG</creator><creator>WANG SHIWEN</creator><creator>XU JIAN</creator><creator>LI JIA</creator><creator>DING LI</creator><creator>LYU ZHIQUAN</creator><creator>ZHU YUNQIAN</creator><creator>ZHOU HAO</creator><creator>WEN SENHAO</creator><scope>EVB</scope></search><sort><creationdate>20180629</creationdate><title>Cross-level data flow tracking method based on windows platform</title><author>XIAO CHONGHUI ; JIA ZIXIAO ; YAO LI ; ZHANG TENG ; LI ZHIHUI ; WANG XIAOQUN ; MA LIYA ; HAN ZHIHUI ; ZHANG SHUAI ; YAN HANBING ; LEI JUN ; GAO CHUAN ; ZHOU YU ; CHEN YANG ; WANG SHIWEN ; XU JIAN ; LI JIA ; DING LI ; LYU ZHIQUAN ; ZHU YUNQIAN ; ZHOU HAO ; WEN SENHAO</author></sort><facets><frbrtype>5</frbrtype><frbrgroupid>cdi_FETCH-epo_espacenet_CN108229172A3</frbrgroupid><rsrctype>patents</rsrctype><prefilter>patents</prefilter><language>chi ; eng</language><creationdate>2018</creationdate><topic>CALCULATING</topic><topic>COMPUTING</topic><topic>COUNTING</topic><topic>ELECTRIC DIGITAL DATA PROCESSING</topic><topic>PHYSICS</topic><toplevel>online_resources</toplevel><creatorcontrib>XIAO CHONGHUI</creatorcontrib><creatorcontrib>JIA ZIXIAO</creatorcontrib><creatorcontrib>YAO LI</creatorcontrib><creatorcontrib>ZHANG TENG</creatorcontrib><creatorcontrib>LI ZHIHUI</creatorcontrib><creatorcontrib>WANG XIAOQUN</creatorcontrib><creatorcontrib>MA LIYA</creatorcontrib><creatorcontrib>HAN ZHIHUI</creatorcontrib><creatorcontrib>ZHANG SHUAI</creatorcontrib><creatorcontrib>YAN HANBING</creatorcontrib><creatorcontrib>LEI JUN</creatorcontrib><creatorcontrib>GAO CHUAN</creatorcontrib><creatorcontrib>ZHOU YU</creatorcontrib><creatorcontrib>CHEN YANG</creatorcontrib><creatorcontrib>WANG SHIWEN</creatorcontrib><creatorcontrib>XU JIAN</creatorcontrib><creatorcontrib>LI JIA</creatorcontrib><creatorcontrib>DING LI</creatorcontrib><creatorcontrib>LYU ZHIQUAN</creatorcontrib><creatorcontrib>ZHU YUNQIAN</creatorcontrib><creatorcontrib>ZHOU HAO</creatorcontrib><creatorcontrib>WEN SENHAO</creatorcontrib><collection>esp@cenet</collection></facets><delivery><delcategory>Remote Search Resource</delcategory><fulltext>fulltext_linktorsrc</fulltext></delivery><addata><au>XIAO CHONGHUI</au><au>JIA ZIXIAO</au><au>YAO LI</au><au>ZHANG TENG</au><au>LI ZHIHUI</au><au>WANG XIAOQUN</au><au>MA LIYA</au><au>HAN ZHIHUI</au><au>ZHANG SHUAI</au><au>YAN HANBING</au><au>LEI JUN</au><au>GAO CHUAN</au><au>ZHOU YU</au><au>CHEN YANG</au><au>WANG SHIWEN</au><au>XU JIAN</au><au>LI JIA</au><au>DING LI</au><au>LYU ZHIQUAN</au><au>ZHU YUNQIAN</au><au>ZHOU HAO</au><au>WEN SENHAO</au><format>patent</format><genre>patent</genre><ristype>GEN</ristype><title>Cross-level data flow tracking method based on windows platform</title><date>2018-06-29</date><risdate>2018</risdate><abstract>The invention relates to a cross-level data flow tracking method based on a windows platform. The method includes the steps: acquiring API (application program interface) information for data exchangebetween a kernel state and a user state of a windows operation system; running a program to be analyzed and executing an instruction of the program to be analyzed; traversing processes in the operation system and acquiring a process with the name consistent with that of a process of the program to be analyzed, and marking the process as a monitored process; marking data generated by executing themonitored process as monitored data of the user state; marking kernel data mapped after input as monitored data of the kernel state if corresponding input parameters are the monitored data of the user state in the API calling process of the program to be analyzed; tracking and analyzing data flow of the monitored data of the user state and the monitored data of the kernel state, and accordingly judging whether the program</abstract><oa>free_for_read</oa></addata></record>
fulltext fulltext_linktorsrc
identifier
ispartof
issn
language chi ; eng
recordid cdi_epo_espacenet_CN108229172A
source esp@cenet
subjects CALCULATING
COMPUTING
COUNTING
ELECTRIC DIGITAL DATA PROCESSING
PHYSICS
title Cross-level data flow tracking method based on windows platform
url https://sfx.bib-bvb.de/sfx_tum?ctx_ver=Z39.88-2004&ctx_enc=info:ofi/enc:UTF-8&ctx_tim=2025-01-17T08%3A09%3A54IST&url_ver=Z39.88-2004&url_ctx_fmt=infofi/fmt:kev:mtx:ctx&rfr_id=info:sid/primo.exlibrisgroup.com:primo3-Article-epo_EVB&rft_val_fmt=info:ofi/fmt:kev:mtx:patent&rft.genre=patent&rft.au=XIAO%20CHONGHUI&rft.date=2018-06-29&rft_id=info:doi/&rft_dat=%3Cepo_EVB%3ECN108229172A%3C/epo_EVB%3E%3Curl%3E%3C/url%3E&disable_directlink=true&sfx.directlink=off&sfx.report_link=0&rft_id=info:oai/&rft_id=info:pmid/&rfr_iscdi=true