Similarity match based rapid detection method for malicious shellcode

A technology of similarity matching and detection method, which is applied in the field of fast detection of malicious shellcode based on similarity matching, can solve the problems of high false negative events, etc., and achieve the effects of improving throughput, reducing detection processing consumption, and increasing detection rate

Inactive Publication Date: 2016-01-13
HARBIN ENG UNIV
View PDF4 Cites 11 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Benefits of technology

In this new method described in this patents, an advanced technique called Simulation Programming (SP) has been developed that uses both hardware-based techniques for detecting attacks against computer networks or other systems with unknown security threats. It improves upon existing methods such as Fuzzy Log Analysis (FLA), XOR logic analysis, etc., which only work well when they have known suspiciest behavioral patterns within their dataset. Additionally, SP also includes various technical means like machine learning models and statistical modeling tools, along with efficient software implementations and programmable processors. Overall, these improvements enhance the effectiveness and efficiency of defense measures implemented across different types of computers and applications.

Problems solved by technology

This patented technical solution described in the patents describes how hackers pose serious risks when accessing sensitive networks such as servers from internet access points like web browsers. These harmful acts aim at stealing valuable resources without being identified during their own activities. To prevent unauthorized entry attempts, various methods were developed over time. One approach involves analyzing the content of certain files called shipping documents (SF) containing hidden bytecodes embedded within themselves. By comparing different versions of SF codes against each other, if they match, indicating potential compromise between the original program design and its executable components. Another technique uses statistical analysis techniques to identify suspended patterns caused by specific parts of the file's functionality. Finally, Dynamic Analysis Techniques are applied to find weaknesses in SFTS encodings.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Similarity match based rapid detection method for malicious shellcode
  • Similarity match based rapid detection method for malicious shellcode
  • Similarity match based rapid detection method for malicious shellcode

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0020] The present invention will be further described below in conjunction with the accompanying drawings.

[0021] The present invention includes:

[0022] Step 1: When testing the data to be tested, a simple judgment will be made on the data to be tested based on similarity matching detection technology to determine whether there are suspicious GetPC and floating-point operation instructions such as call, jmp, and fnstenv instructions. According to the judgment result, if there is a suspicious instruction, it should use encoding processing, and determine the start of the simulation execution detection position using the decoder, improve the execution efficiency of the simulator, and reduce the detection scale of the data to be tested. When these steps are completed, go to step 2;

[0023] Step 2: At the initial detection position determined in the first step, call the decoder to perform simulated execution detection, and find out whether there are loop decoding instruction...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention relates to a similarity match based rapid detection method for a malicious shellcode, and advantages of traditional dynamic and static detection technologies are combined in the rapid detection method. The rapid detection method comprises that data to be detected is determined; a decoder is called to implement simulated execution detection; simulatied detection is carried out on the data to be detected and a sample library via a Shingle algorithm; and when the similarity coefficient is greater than a threshold 40%, it can be determined that attack behavior of the malicious shellcode exists in the data to be detected, and early warning is made. According to the rapid detection method, a simulator which implements deep simulated execution and system function Hook is not needed, the detection consumption of the dynamic simulated detection technology is further reduced, the throughput of detection data is improved, the detection speed for multi-state malicious codes is improved, and influence on the network speed is reduced.

Description

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Owner HARBIN ENG UNIV
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products