Unlock instant, AI-driven research and patent intelligence for your innovation.

Target program processing method, processing device and cloud service equipment

A technology of a target program and a processing method, applied in the computer field, can solve problems such as inability to unpack, load PE files, and nonexistence, and achieve the effect of reducing manual participation, ensuring security, and ensuring accuracy

Active Publication Date: 2015-06-17
BEIJING QIHOO TECH CO LTD
View PDF3 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

When performing dynamic unpacking, many PE files need to import third-party function libraries before they can be loaded into memory for execution. The so-called third-party function libraries refer to non-system function libraries that need to be imported when PE files are loaded into memory. The third-party function library does not exist in the isolation environment, so the Windows operating system cannot load the PE file into the memory, and it cannot be unpacked

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Target program processing method, processing device and cloud service equipment
  • Target program processing method, processing device and cloud service equipment
  • Target program processing method, processing device and cloud service equipment

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0042] The implementation of the present application will be described in detail below in conjunction with the drawings and examples, so that the realization process of how the present application uses technical means to solve technical problems and achieve technical effects can be fully understood and implemented accordingly.

[0043] This application guarantees the loading of target files by constructing a third-party function library by itself, so that it can unpack and transfer to scan in an anti-virus environment lacking a third-party function library; the anti-virus environment is an isolated environment, and only guarantees that the basic files can be loaded System function library.

[0044] After the scanning of the target file, it can be known whether the target file is malicious, and the target file can be processed according to the scanning result; for example, the target file is malicious, and the processing includes cleaning or isolation, wherein the cleaning opera...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The application discloses a target program processing method, a processing device and cloud service equipment. The target program processing method comprises the steps of: obtaining a name of a third-party function library and the name of a function included in the third-party function library, wherein the third-party function library is the third-party function library to be introduced when a target program is loaded to a memory; constructing a blank function library, and faking the blank function library into the third-party function library according to the name of the third-party function library and the name of the function included in the third-party function library; introducing the faked third-party function library and reading the corresponding function name so as to load the target program to the memory; and shucking and scanning the target program, and processing the target program according to the scanning result. According to the application, loading of the target file is ensured by automatically constructing the third-party function library, so that shucking and scanning can be performed in an antivirus environment without the third-party function library.

Description

technical field [0001] The present application belongs to the field of computers, and in particular, relates to an object program processing method, processing device and cloud service equipment. Background technique [0002] PE files are program files on the Windows operating system and are called Portable Executable (PE, Portable Execute) files. Common PE files include: EXE, DLL, OCX, SYS, COM and other files. [0003] Packing a PE file requires a special algorithm to compress and encrypt resources in the PE file, and the PE file after packing can run independently. After the shell code attached to the original program of the PE file is loaded into the memory through the Windows loader at runtime, it is executed before the original program of the PE file to obtain the control right of the PE file. During the execution of the shell code, the original program of the PE file is decrypted, Decompression, this restoration process is completely hidden, and it is all completed ...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): G06F21/51G06F21/56
Inventor 程文坤
Owner BEIJING QIHOO TECH CO LTD