CN106557701B - 基于虚拟机的内核漏洞检测方法及装置 - Google Patents
基于虚拟机的内核漏洞检测方法及装置 Download PDFInfo
- Publication number
- CN106557701B CN106557701B CN201611070377.XA CN201611070377A CN106557701B CN 106557701 B CN106557701 B CN 106557701B CN 201611070377 A CN201611070377 A CN 201611070377A CN 106557701 B CN106557701 B CN 106557701B
- Authority
- CN
- China
- Prior art keywords
- detection
- file
- sample
- communication agent
- virtual machine
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000001514 detection method Methods 0.000 title claims abstract description 530
- 238000000034 method Methods 0.000 claims abstract description 619
- 230000008569 process Effects 0.000 claims abstract description 431
- 238000004891 communication Methods 0.000 claims abstract description 82
- 238000012360 testing method Methods 0.000 claims abstract description 31
- 238000003860 storage Methods 0.000 claims abstract description 26
- 244000035744 Hura crepitans Species 0.000 claims description 36
- 238000002955 isolation Methods 0.000 claims description 25
- 230000005540 biological transmission Effects 0.000 claims description 12
- 238000007650 screen-printing Methods 0.000 claims description 4
- 239000011800 void material Substances 0.000 claims description 2
- 230000007246 mechanism Effects 0.000 abstract description 10
- 230000006870 function Effects 0.000 description 96
- 239000003795 chemical substances by application Substances 0.000 description 51
- 230000006399 behavior Effects 0.000 description 22
- 238000005516 engineering process Methods 0.000 description 20
- 238000012544 monitoring process Methods 0.000 description 13
- 239000000872 buffer Substances 0.000 description 12
- 230000026676 system process Effects 0.000 description 12
- 230000000977 initiatory effect Effects 0.000 description 10
- 230000000694 effects Effects 0.000 description 8
- 238000009826 distribution Methods 0.000 description 7
- 238000007689 inspection Methods 0.000 description 7
- 230000003993 interaction Effects 0.000 description 7
- 230000015654 memory Effects 0.000 description 7
- 230000006837 decompression Effects 0.000 description 5
- 238000001914 filtration Methods 0.000 description 5
- 230000008901 benefit Effects 0.000 description 4
- 238000010586 diagram Methods 0.000 description 4
- 238000012545 processing Methods 0.000 description 4
- 230000004044 response Effects 0.000 description 4
- 230000006641 stabilisation Effects 0.000 description 4
- 238000011105 stabilization Methods 0.000 description 4
- 238000004088 simulation Methods 0.000 description 3
- 238000004458 analytical method Methods 0.000 description 2
- 230000008859 change Effects 0.000 description 2
- 238000004590 computer program Methods 0.000 description 2
- 238000005315 distribution function Methods 0.000 description 2
- 238000004519 manufacturing process Methods 0.000 description 2
- 230000002265 prevention Effects 0.000 description 2
- 230000003068 static effect Effects 0.000 description 2
- 239000004575 stone Substances 0.000 description 2
- 238000012800 visualization Methods 0.000 description 2
- 241001269238 Data Species 0.000 description 1
- 241000700605 Viruses Species 0.000 description 1
- 238000003556 assay Methods 0.000 description 1
- 238000012098 association analyses Methods 0.000 description 1
- 238000012550 audit Methods 0.000 description 1
- 230000003542 behavioural effect Effects 0.000 description 1
- 230000007547 defect Effects 0.000 description 1
- 230000007123 defense Effects 0.000 description 1
- ZXQYGBMAQZUVMI-GCMPRSNUSA-N gamma-cyhalothrin Chemical compound CC1(C)[C@@H](\C=C(/Cl)C(F)(F)F)[C@H]1C(=O)O[C@H](C#N)C1=CC=CC(OC=2C=CC=CC=2)=C1 ZXQYGBMAQZUVMI-GCMPRSNUSA-N 0.000 description 1
- 238000003780 insertion Methods 0.000 description 1
- 230000037431 insertion Effects 0.000 description 1
- 238000007726 management method Methods 0.000 description 1
- 238000006748 scratching Methods 0.000 description 1
- 230000002393 scratching effect Effects 0.000 description 1
- XLYOFNOQVPJJNP-UHFFFAOYSA-N water Substances O XLYOFNOQVPJJNP-UHFFFAOYSA-N 0.000 description 1
- 239000002023 wood Substances 0.000 description 1
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
- G06F21/577—Assessing vulnerabilities and evaluating computer system security
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/52—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow
- G06F21/53—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow by executing in a restricted environment, e.g. sandbox or secure virtual machine
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Computing Systems (AREA)
- Computer And Data Communications (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims (12)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201611070377.XA CN106557701B (zh) | 2016-11-28 | 2016-11-28 | 基于虚拟机的内核漏洞检测方法及装置 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201611070377.XA CN106557701B (zh) | 2016-11-28 | 2016-11-28 | 基于虚拟机的内核漏洞检测方法及装置 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN106557701A CN106557701A (zh) | 2017-04-05 |
CN106557701B true CN106557701B (zh) | 2019-09-06 |
Family
ID=58445625
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201611070377.XA Active CN106557701B (zh) | 2016-11-28 | 2016-11-28 | 基于虚拟机的内核漏洞检测方法及装置 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN106557701B (zh) |
Families Citing this family (14)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN107506641A (zh) * | 2017-09-30 | 2017-12-22 | 北京奇虎科技有限公司 | 沙箱管理方法及装置、计算设备、存储介质 |
CN107742080B (zh) * | 2017-09-30 | 2021-06-08 | 北京奇虎科技有限公司 | 针对虚拟化环境的漏洞挖掘方法及装置 |
CN111124396B (zh) * | 2018-11-01 | 2023-04-07 | 北京国双科技有限公司 | 网站数据处理方法和装置 |
CN111343132B (zh) * | 2018-12-19 | 2022-03-01 | 华为技术有限公司 | 文件传输检测方法及装置、存储介质 |
CN109753791B (zh) * | 2018-12-29 | 2024-07-26 | 北京奇虎科技有限公司 | 恶意程序检测方法及装置 |
CN110096440B (zh) * | 2019-04-26 | 2023-04-18 | 厦门网宿有限公司 | 一种日志处理方法及装置 |
CN112446027B (zh) * | 2019-08-27 | 2023-04-14 | 中移(苏州)软件技术有限公司 | 一种配置核查方法、装置、电子设备和计算机存储介质 |
CN112241309B (zh) * | 2020-10-21 | 2022-04-01 | 海光信息技术股份有限公司 | 一种数据安全方法、装置、cpu、芯片及计算机设备 |
CN112632529A (zh) * | 2020-12-23 | 2021-04-09 | 北京鸿腾智能科技有限公司 | 漏洞识别方法、设备、存储介质及装置 |
CN112532658B (zh) * | 2021-02-08 | 2021-05-07 | 腾讯科技(深圳)有限公司 | 云网络逃逸事件扫描方法、装置及计算机可读存储介质 |
CN113206850B (zh) * | 2021-04-30 | 2022-09-16 | 北京恒安嘉新安全技术有限公司 | 恶意样本的报文信息获取方法、装置、设备及存储介质 |
CN114785542B (zh) * | 2022-03-10 | 2023-05-23 | 安芯网盾(北京)科技有限公司 | 一种木马检测方法、系统、电子设备和存储介质 |
CN116305091B (zh) * | 2023-03-31 | 2024-11-08 | 华能信息技术有限公司 | 一种反逃逸检测方法 |
CN116560858A (zh) * | 2023-07-07 | 2023-08-08 | 北京蔚领时代科技有限公司 | Vr云服务器容器隔离方法及系统 |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN103810222A (zh) * | 2012-11-15 | 2014-05-21 | 北京金山安全软件有限公司 | 样本文件的处理方法及装置 |
CN103839003A (zh) * | 2012-11-22 | 2014-06-04 | 腾讯科技(深圳)有限公司 | 恶意文件检测方法及装置 |
CN106130966A (zh) * | 2016-06-20 | 2016-11-16 | 北京奇虎科技有限公司 | 一种漏洞挖掘检测方法、服务器、装置和系统 |
CN106155880A (zh) * | 2015-03-27 | 2016-11-23 | 中国科学院信息工程研究所 | 一种基于策略的自动化程序分析系统和方法 |
-
2016
- 2016-11-28 CN CN201611070377.XA patent/CN106557701B/zh active Active
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN103810222A (zh) * | 2012-11-15 | 2014-05-21 | 北京金山安全软件有限公司 | 样本文件的处理方法及装置 |
CN103839003A (zh) * | 2012-11-22 | 2014-06-04 | 腾讯科技(深圳)有限公司 | 恶意文件检测方法及装置 |
CN106155880A (zh) * | 2015-03-27 | 2016-11-23 | 中国科学院信息工程研究所 | 一种基于策略的自动化程序分析系统和方法 |
CN106130966A (zh) * | 2016-06-20 | 2016-11-16 | 北京奇虎科技有限公司 | 一种漏洞挖掘检测方法、服务器、装置和系统 |
Also Published As
Publication number | Publication date |
---|---|
CN106557701A (zh) | 2017-04-05 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN106557701B (zh) | 基于虚拟机的内核漏洞检测方法及装置 | |
Wei et al. | Deep ground truth analysis of current android malware | |
CN106778243A (zh) | 基于虚拟机的内核漏洞检测文件保护方法及装置 | |
EP3479281B1 (en) | Method and computer system for determining a threat score | |
JP7115526B2 (ja) | 分析システム、方法、及び、プログラム | |
CN106778244A (zh) | 基于虚拟机的内核漏洞检测进程保护方法及装置 | |
CA3017936A1 (en) | System and method for reverse command shell detection | |
WO2017160765A1 (en) | System and method for process hollowing detection | |
US11853425B2 (en) | Dynamic sandbox scarecrow for malware management | |
CN106778242A (zh) | 基于虚拟机的内核漏洞检测方法及装置 | |
WO2018004572A1 (en) | Sandbox environment for document preview and analysis | |
CN110647744A (zh) | 使用特定于对象的文件系统视图识别和提取关键危害取证指标 | |
JP2014238870A (ja) | 挙動サンドボックスのためのシステム及び方法 | |
WO2009032379A1 (en) | Methods and systems for providing trap-based defenses | |
CN106778246A (zh) | 沙箱虚拟化的检测方法及检测装置 | |
Rrushi | NIC displays to thwart malware attacks mounted from within the OS | |
Barlev et al. | Secure yet usable: Protecting servers and Linux containers | |
Peddoju et al. | File integrity monitoring tools: Issues, challenges, and solutions | |
CN103970574B (zh) | office程序的运行方法及装置、计算机系统 | |
US20060053492A1 (en) | Software tracking protection system | |
Mishra et al. | Multi tree view of complex attack–stuxnet | |
Bajo | An analysis of offensive capabilities of ebpf and implementation of a rootkit | |
Grammatikakis et al. | System threats | |
Lenhard et al. | Dangerous Software | |
Zeltser | Analyzing malicious software |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
GR01 | Patent grant | ||
GR01 | Patent grant | ||
TR01 | Transfer of patent right |
Effective date of registration: 20211210 Address after: 300450 No. 9-3-401, No. 39, Gaoxin 6th Road, Binhai Science Park, high tech Zone, Binhai New Area, Tianjin Patentee after: 3600 Technology Group Co.,Ltd. Address before: 100088 room 112, block D, 28 new street, new street, Xicheng District, Beijing (Desheng Park) Patentee before: BEIJING QIHOO TECHNOLOGY Co.,Ltd. Patentee before: Qizhi software (Beijing) Co.,Ltd. |
|
TR01 | Transfer of patent right | ||
TR01 | Transfer of patent right |
Effective date of registration: 20230711 Address after: 1765, floor 17, floor 15, building 3, No. 10 Jiuxianqiao Road, Chaoyang District, Beijing 100015 Patentee after: Beijing Hongxiang Technical Service Co.,Ltd. Address before: 300450 No. 9-3-401, No. 39, Gaoxin 6th Road, Binhai Science Park, high tech Zone, Binhai New Area, Tianjin Patentee before: 3600 Technology Group Co.,Ltd. |
|
TR01 | Transfer of patent right | ||
CP03 | Change of name, title or address |
Address after: 1765, floor 17, floor 15, building 3, No. 10 Jiuxianqiao Road, Chaoyang District, Beijing 100015 Patentee after: Beijing 360 Zhiling Technology Co.,Ltd. Country or region after: China Address before: 1765, floor 17, floor 15, building 3, No. 10 Jiuxianqiao Road, Chaoyang District, Beijing 100015 Patentee before: Beijing Hongxiang Technical Service Co.,Ltd. Country or region before: China |
|
CP03 | Change of name, title or address |