Invention Grant
US08627478B2 Method and apparatus for inspecting non-portable executable files 有权
检查非便携式可执行文件的方法和装置

  • Patent Title: Method and apparatus for inspecting non-portable executable files
  • Patent Title (中): 检查非便携式可执行文件的方法和装置
  • Application No.: US13887610
    Application Date: 2013-05-06
  • Publication No.: US08627478B2
    Publication Date: 2014-01-07
  • Inventor: Cha Sung LimJu Seok Lee
  • Applicant: Ahnlab, Inc.
  • Applicant Address: KR
  • Assignee: Ahnlab, Inc.
  • Current Assignee: Ahnlab, Inc.
  • Current Assignee Address: KR
  • Agency: Bacon & Thomas, PLLC
  • Priority: KR10-2012-0050156 20120511
  • Main IPC: H04L9/00
  • IPC: H04L9/00
Method and apparatus for inspecting non-portable executable files
Abstract:
An apparatus for inspecting a non-PE file includes a data loading unit configured to load candidate malicious address information related to a malicious code of the non-PE file; and a program link unit configured to acquire normal address range information of a module being loaded on a memory when an application program adapted for the non-PE file is executed and set up a candidate malicious address corresponding to the candidate malicious address information to be a breakpoint of the application program. Further, the apparatus includes a malicious code determination unit configured to determine whether a next execution address is within the normal address range information when there occurs an event derived from the breakpoint.
Public/Granted literature
Information query
Patent Agency Ranking
0/0