一种智能恶意代码分析方法、系统、介质及产品

By combining packed code detection, static analysis, and dynamic sandbox monitoring with threat database queries, the system addresses the shortcomings of traditional malware detection in terms of accuracy and source tracing, achieving efficient identification and source tracing of malware.

CN121935908BActive Publication Date: 2026-07-17NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT
Filing Date
2026-01-07
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Traditional malware detection methods are insufficient in detecting malware that is highly concealed and mutates rapidly, resulting in low detection accuracy and difficulty in effectively identifying unknown or variant malware.

Method used

The system obtains raw code data through packing detection and automatic unpacking, extracts static features and dynamic behavior data through static analysis, uses an adaptive sandbox environment for monitoring and defense, generates comprehensive source tracing results, and performs matching queries in conjunction with a threat database.

Benefits of technology

It improves the accuracy and depth of malicious code detection, enhances the ability to respond to advanced threats, and provides comprehensive intelligent protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121935908B_ABST
    Figure CN121935908B_ABST
Patent Text Reader

Abstract

一种智能恶意代码分析方法、系统、介质及产品,涉及网络安全领域。在该方法中,获取恶意代码样本,并对恶意代码样本进行加壳检测和自动脱壳,得到原始代码数据;对原始代码数据进行静态分析,得到恶意代码样本的静态特征和代码指令,生成静态代码锚点标识,并对预设自适应沙箱环境内的操作系统API进行监控点注入,得到目标自适应沙箱环境;在目标自适应沙箱环境中执行恶意代码样本以进行动态分析,生成动态行为数据,并对沙箱逃逸行为进行防御;将静态特征、动态行为数据与外部威胁库进行匹配查询,得到与恶意代码样本关联的综合溯源结果。实施本申请提供的技术方案,提高了恶意代码检测的准确性。
Need to check novelty before this filing date? Find Prior Art