WO2019229503A1 - Détection de logiciel malveillant spécifique à une application dans un système de co-traitement - Google Patents
Détection de logiciel malveillant spécifique à une application dans un système de co-traitement Download PDFInfo
- Publication number
- WO2019229503A1 WO2019229503A1 PCT/IB2018/053912 IB2018053912W WO2019229503A1 WO 2019229503 A1 WO2019229503 A1 WO 2019229503A1 IB 2018053912 W IB2018053912 W IB 2018053912W WO 2019229503 A1 WO2019229503 A1 WO 2019229503A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- application
- malware
- memory
- memory dump
- general purpose
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/567—Computer malware detection or handling, e.g. anti-virus arrangements using dedicated hardware
Definitions
- the general purpose processor maintains a hash map per application consisting of the malware name or identifier as the key and the value as the list of references or physical addresses of the memory dumps associated with the malware.
- Application specific malware detection service running on a co-processing system consisting of a general purpose processor to which a hardware accelerator is coupled receives an application identifier or an application specific tag along with the application memory dump for analysis.
- Memory dump of the application affected by the malware is offloaded by the general purpose processor to the hardware accelerator coupled to the general purpose processor by storing application memory dump and a reference or the physical address of the hash map corresponding to the application to system memory and indicating to the hardware accelerator that the application memory dump is available for content scanning.
- the hardware accelerator then scans the application memory dump to derive various characteristics related to the application memory dump and matches it against the characteristics of different memory dumps of different malware obtained from the hash map corresponding to the application to detect the application specific malware.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Virology (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Debugging And Monitoring (AREA)
Abstract
Dans la présente invention, le processeur polyvalent maintient une carte de hachage par application comprenant le nom ou l'identificateur de logiciel malveillant en tant que clé et la valeur sous la forme de la liste de références ou d'adresses physiques des déchargements de mémoire associées au logiciel malveillant. Le déchargement de mémoire de l'application affectée par le logiciel malveillant est déchargée par le processeur universel vers l'accélérateur matériel couplé au processeur universel en stockant un déchargement de mémoire d'application et une référence ou l'adresse physique de la carte de hachage correspondant à l'application à la mémoire système et indiquant à l'accélérateur matériel que le déchargement de mémoire d'application est disponible pour un balayage de contenu. L'accélérateur matériel balaye ensuite le déchargement de mémoire d'application pour dériver des caractéristiques associées au déchargement de mémoire d'application et les met en correspondance avec les caractéristiques de différents déchargements de mémoire de différents logiciels malveillants obtenus à partir de la carte de hachage correspondant à l'application pour détecter les logiciels malveillants spécifiques à l'application.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/IB2018/053912 WO2019229503A1 (fr) | 2018-05-31 | 2018-05-31 | Détection de logiciel malveillant spécifique à une application dans un système de co-traitement |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/IB2018/053912 WO2019229503A1 (fr) | 2018-05-31 | 2018-05-31 | Détection de logiciel malveillant spécifique à une application dans un système de co-traitement |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2019229503A1 true WO2019229503A1 (fr) | 2019-12-05 |
Family
ID=68696845
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/IB2018/053912 Ceased WO2019229503A1 (fr) | 2018-05-31 | 2018-05-31 | Détection de logiciel malveillant spécifique à une application dans un système de co-traitement |
Country Status (1)
| Country | Link |
|---|---|
| WO (1) | WO2019229503A1 (fr) |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20120079596A1 (en) * | 2010-08-26 | 2012-03-29 | Verisign, Inc. | Method and system for automatic detection and analysis of malware |
| US8347386B2 (en) * | 2008-10-21 | 2013-01-01 | Lookout, Inc. | System and method for server-coupled malware prevention |
| US20160191548A1 (en) * | 2008-05-07 | 2016-06-30 | Cyveillance, Inc. | Method and system for misuse detection |
-
2018
- 2018-05-31 WO PCT/IB2018/053912 patent/WO2019229503A1/fr not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20160191548A1 (en) * | 2008-05-07 | 2016-06-30 | Cyveillance, Inc. | Method and system for misuse detection |
| US8347386B2 (en) * | 2008-10-21 | 2013-01-01 | Lookout, Inc. | System and method for server-coupled malware prevention |
| US20120079596A1 (en) * | 2010-08-26 | 2012-03-29 | Verisign, Inc. | Method and system for automatic detection and analysis of malware |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| USRE47558E1 (en) | System, method, and computer program product for automatically identifying potentially unwanted data as unwanted | |
| Wiederhold et al. | First detection of TR34 L98H and TR46 Y121F T289A Cyp51 mutations in Aspergillus fumigatus isolates in the United States | |
| GB2594856A (en) | Secure multiparty detection of sensitive data using private set intersection (PSI) | |
| MX2020014325A (es) | Sistemas y métodos para determinar un evento malicioso potencial. | |
| BRPI0606200A2 (pt) | sistema de detecção cognitiva de alterações | |
| BR112019000398A2 (pt) | realidade virtual, aumentada e mista | |
| EP4220415A3 (fr) | Procede et appareil de compression d'adresses | |
| RU2011147542A (ru) | Система и способ для исправления антивирусных записей | |
| EP4564160A3 (fr) | Appareils matériels et procédés de détection de corruption de mémoire | |
| GB2582477A (en) | Accessing gateway management console | |
| NO20092482L (no) | Systemanalyse og handtering | |
| WO2008127540A3 (fr) | Systèmes, procédés et produits programmes informatiques destinés à générer des géocodes de référence pour des adresses de points | |
| CN105897752B (zh) | 未知域名的安全检测方法及装置 | |
| EP2472822A3 (fr) | Procédé et système pour estimer la fiabilité de listes noires d'ordinateurs infectés de botnets | |
| WO2007069246A3 (fr) | Systeme et procede pour inspecter un code executable produit de maniere dynamique | |
| BR102014011433A8 (pt) | sistema, método e aparelho para processamento de dados | |
| CN113162953B (zh) | 网络威胁报文检测及溯源取证方法和装置 | |
| JP2013532328A5 (fr) | ||
| PH12018501475A1 (en) | Method and device for aquiring abbreviated name of point of interest on map | |
| TW200801568A (en) | A method, use of said method and arrangements in an electronic support measures system | |
| GB2559082A (en) | In-vehicle haptic output | |
| GB2560851A (en) | Memory synchronization filter | |
| GB2598222A (en) | Testing storage protection hardware in secure virtual machine environment | |
| RU2017105533A (ru) | Обнаружение вредоносного программного обеспечения с перекрестным обзором | |
| US8627461B2 (en) | System, method, and computer program product for verifying an identification of program information as unwanted |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 18921050 Country of ref document: EP Kind code of ref document: A1 |