Malware detection method and malware detection apparatus
Abstract:
A malware detection method and a malware detection apparatus are provided. The method includes running to-be-detected software in a sandbox, and recording at least one operation; and in a process of recording the at least one operation, when it is detected that any interface that has a delay attribute in the sandbox is called, determining whether delay duration corresponding to a first delay length parameter of the called interface is greater than preset duration. If the delay duration corresponding to the first delay length parameter is greater than the preset duration, delay duration of delay execution is reduced to enable the malicious behavior to be executed in the process of recording the at least one operation executed within the preset duration after the to-be-detected software starts to run, and accordingly, the malicious behavior may be exposed in advance.
Public/Granted literature
Information query
Patent Agency Ranking
0/0