首页> 外国专利> Process analysis apparatus, process analysis method, and process analysis for determining input/output relation of a block of execution trace to detect potential malware

Process analysis apparatus, process analysis method, and process analysis for determining input/output relation of a block of execution trace to detect potential malware

机译:用于确定执行跟踪块的输入/输出关系以检测潜在恶意软件的过程分析装置,过程分析方法和过程分析

摘要

The present invention relates to a process analysis apparatus for analyzing a process executed in an information processing unit and extracting encryption logic such as an encryption function or a decryption function used in the process. The process analysis apparatus is provided with an execution trace acquisition section to acquire an execution trace of a process to be analyzed; a block extraction section to extract, from the execution trace, a block that is a processing unit indicating a loop structure; a block information extraction section to extract, from the block, block information including input information and output information; and a block information analysis section to generate characteristic determination information for determining a characteristic of an input/output relation of the block, using the input information or the output information of the block information, analyzing the input/output relation of the block, using the characteristic determination information, and determining the block which indicates a characteristic of an input/output relation of an encryption function or a decryption function, as the encryption logic.
机译:本发明涉及一种过程分析装置,用于分析在信息处理单元中执行的过程并提取在该过程中使用的加密逻辑,例如加密功能或解密功能。工序分析装置具备执行轨迹取得部,取得要分析的工序的执行轨迹。块提取部分从执行跟踪中提取作为表示循环结构的处理单元的块;块信息提取部分,从该块中提取包括输入信息和输出信息的块信息;块信息分析部分,使用块信息的输入信息或输出信息,生成用于确定块的输入/输出关系的特性的特性确定信息,并使用该信息来分析块的输入/输出关系。特征确定信息,并确定指示加密功能或解密功能的输入/输出关系的特征的块作为加密逻辑。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号