Method and system for determining malicious code based on calling relation
A malicious code and call relationship technology, applied in the malicious code judgment method and system field based on the call relationship, can solve the problems of low detection efficiency, missing the best time to intercept viruses, and increasing the detection cost of malicious samples, so as to reduce the degree of distortion, The effect of improving accuracy and efficiency
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Example Embodiment
[0029] The present invention provides an embodiment of a method and system for judging malicious code based on a calling relationship, in order to enable those skilled in the art to better understand the technical solutions in the embodiments of the present invention, and to enable the above-mentioned objectives, features and The advantages can be more obvious and easy to understand. The technical solution of the present invention will be further described in detail below in conjunction with the accompanying drawings:
[0030] The present invention first provides a method for judging malicious code based on the calling relationship in Embodiment 1, such as figure 1 Shown, including:
[0031] S11: Decompile the program to be tested and obtain pseudo code.
[0032] S12: Parse the pseudo code and build a call structure tree.
[0033] Specifically, the pseudo code can be parsed to obtain information about each function, and a call structure tree can be constructed based on the information...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap