METHOD FOR DETECTING MALWARE

PROBLEM TO BE SOLVED: To prevent the installation of malware by detecting a behavior associated with the malware.SOLUTION: Each time an inspection object process code performs system call, it is detected, and the call site is further detected. The section of the code in an area in the periphery of t...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: AMIT KLEIN, GAL FRISHMAN, ELDAN BEN-HAIM
Format: Patent
Sprache:eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:PROBLEM TO BE SOLVED: To prevent the installation of malware by detecting a behavior associated with the malware.SOLUTION: Each time an inspection object process code performs system call, it is detected, and the call site is further detected. The section of the code in an area in the periphery of the site, and/or in a branch relating to the site is analyzed, and the property of the analysis object portion of the code is compared with a defined software code pattern in order to determine whether or not an inspection object process code is made to correspond to one of the defined software code patterns. Then, the inspection object process codes are classified in accordance with the comparison result.