首页> 外国专利> ATTACK CODE DETECTION DEVICE, ATTACK CODE DETECTION METHOD, AND ATTACK CODE DETECTION PROGRAM

ATTACK CODE DETECTION DEVICE, ATTACK CODE DETECTION METHOD, AND ATTACK CODE DETECTION PROGRAM

机译:攻击代码检测装置,攻击代码检测方法和攻击代码检测程序

摘要

An attack code detection device (10) includes a learning unit (123) configured to generate a model that learns, using a known labeled malicious document file (100) including an ROP code, as learning data, a feature of a byte sequence being a component of a document file, and a feature of a byte sequence being a component of an ROP code, a detection unit (124) configured to detect the ROP code included in an inspection target unknown document file (200), based on the model, and a malignancy determination unit (125) configured to determine, based on a detection result, whether the inspection target unknown document file (200) is a malicious data series that executes attack using ROP.
机译:攻击代码检测设备(10)包括学习单元(123),该学习单元被配置为生成模型,该模型使用包括ROP代码的已知标记恶意文档文件(100)作为学习数据来学习字节序列的特征。检测单元(124)被配置为基于模型检测包括在检查目标未知文档文件(200)中的ROP代码,恶性判定单元(125),基于检测结果,判定所述检查对象未知文档文件(200)是否为利用ROP进行攻击的恶意数据系列。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号