Invention Grant
- Patent Title: Method and apparatus for inspecting non-portable executable files
- Patent Title (中): 检查非便携式可执行文件的方法和装置
-
Application No.: US13887610Application Date: 2013-05-06
-
Publication No.: US08627478B2Publication Date: 2014-01-07
- Inventor: Cha Sung Lim , Ju Seok Lee
- Applicant: Ahnlab, Inc.
- Applicant Address: KR
- Assignee: Ahnlab, Inc.
- Current Assignee: Ahnlab, Inc.
- Current Assignee Address: KR
- Agency: Bacon & Thomas, PLLC
- Priority: KR10-2012-0050156 20120511
- Main IPC: H04L9/00
- IPC: H04L9/00

Abstract:
An apparatus for inspecting a non-PE file includes a data loading unit configured to load candidate malicious address information related to a malicious code of the non-PE file; and a program link unit configured to acquire normal address range information of a module being loaded on a memory when an application program adapted for the non-PE file is executed and set up a candidate malicious address corresponding to the candidate malicious address information to be a breakpoint of the application program. Further, the apparatus includes a malicious code determination unit configured to determine whether a next execution address is within the normal address range information when there occurs an event derived from the breakpoint.
Public/Granted literature
- US20130305373A1 METHOD AND APPARATUS FOR INSPECTING NON-PORTABLE EXECUTABLE FILES Public/Granted day:2013-11-14
Information query