Method and device for detecting malicious remote procedure tracing calling behaviors
A technology of remote procedure call and detection method, applied in the direction of multi-program device, inter-program communication, program control design, etc., can solve problems such as interference detection of malicious behavior, false alarm, etc., to ensure accuracy, speed up processing flow, save money The effect of system resources
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0030] The present invention will be further described below in conjunction with the accompanying drawings, but the protection scope of the present invention is not limited to the following description.
[0031] Such as figure 1 and figure 2 As shown, the present invention relates to a detection method of a malicious remote procedure traceability call behavior. By intercepting the remote procedure call, the call interface GUID, ProcNum, call parameters, client process ID and thread ID can be obtained, and the current process will obtain the The information sent to the server module, the service module will judge the obtained information, and mainly judge whether it is a malicious call through the process ID and thread ID of the client. If it is a malicious remote procedure call, it will record the complete remote procedure call; and for non-malicious calls, use the traceability method to find the real request initiator, and further obtain a call chain of the current remote p...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 

