Looking for breakthrough ideas for innovation challenges? Try Patsnap Eureka!

Method and system for sandbox detection and alarm based on host characteristics

A host and sandbox technology, applied in the field of malicious program detection technology and network security, can solve the problems of ineffective detection of malicious program detection, defects in malicious programs, etc., achieve low false positive rate and avoid false negative effects

Inactive Publication Date: 2017-09-12
STATE GRID CORP OF CHINA +3
View PDF7 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0008] The purpose of the present invention is to provide a sandbox detection and alarm method and system based on host characteristics, which are used to solve the problems in the prior art that malicious programs cannot be effectively detected and there are defects in detecting malicious programs

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method and system for sandbox detection and alarm based on host characteristics
  • Method and system for sandbox detection and alarm based on host characteristics
  • Method and system for sandbox detection and alarm based on host characteristics

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0062] In order to make the object, technical solution and advantages of the present invention clearer, various embodiments of the present invention will be described in detail below in conjunction with the accompanying drawings. However, those of ordinary skill in the art can understand that, in each implementation manner of the present invention, many technical details are provided for readers to better understand the present application. However, even without these technical details and various changes and modifications based on the following implementation modes, the technical solutions claimed in the claims of the present application can be realized.

[0063] The first embodiment of the present invention relates to a sandbox detection and alarm method based on host characteristics, such as figure 1 As shown, the application of this embodiment is based on a computer hardware system and a virtual machine. The computer hardware system can run a user operating system. The vir...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention provides a sandbox detection alarming method and a sandbox detection alarming system based on main engine characteristic. The method is characterized by comprising following steps: inserting a virtual machine monitor between a user operating system and a computer hardware system, the virtual machine monitor offers a virtual hardware platform completely simulating the computer hardware system for the virtual machine, and the user operating system runs on the virtual hardware platform; tracking and detecting the main engine characteristic of the virtual system when unknown program to be detected runs on the virtual machine; recognizing the alarm level according to the tracking detection result of the main engine characteristic of the virtual system, generating alarm information being corresponding to the alarm level, and recording the unknown program to be detected in a log information mode. The sandbox detection alarming method and the sandbox detection alarming system based on main engine characteristic performs the unknown program to be detected in the virtual machine monitoring environment for finding rogue program and monitoring the entire attack life cycle of the rogue program.

Description

technical field [0001] The invention relates to malicious program detection technology and the field of network security, in particular to a sandbox detection and alarm method and system based on host characteristics. Background technique [0002] Information and Internet technologies have changed the way people acquire knowledge and communicate. Enterprises also use these new technologies to greatly improve employee efficiency, improve operational capabilities, and create new market opportunities. However, these technologies also increase the vulnerability of organizations to attacks. Therefore, it is necessary to continuously improve malicious program detection methods to deal with these potential or ongoing threats. For example, the State Grid Corporation, as an important backbone enterprise related to national energy security and the lifeline of the national economy, undertakes the basic mission of providing safe and sustainable power supply for economic and social devel...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): G06F21/56G06F21/53
Inventor 刘志永王红凯张旭东夏正敏伍军戴波龚小刚李建华
Owner STATE GRID CORP OF CHINA
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Patsnap Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Patsnap Eureka Blog
Learn More
PatSnap group products