EP2034422A2

Apparatus and method for detecting malicious process

Abstract

Provided are an apparatus and method for detecting a malicious process. The apparatus includes: a process monitoring unit for monitoring a process generated in a computing environment; a target process setting unit for previously setting a test target process among the processes confirmed by the process monitoring unit; a process generation time change monitoring unit for monitoring if the target process set by the target process setting unit requests to change a generation time; a generation time change preventing unit for preventing a change in the generation time of the target process when the target process requests to change the generation time; and a malicious process detecting unit for determining that a child process of the target process set by the target process setting unit is a malicious process if the child process is generated within a predetermined reference time.

EP2034422A2, drawing sheet 1
Sheet 1 of 5

Term

Projected expiry 31 July 2028.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

13 claims: 3 independent, 10 dependent

  1. 1
    An apparatus for detecting a malicious process, comprising:a process monitoring unit for monitoring a process generated in a computing environment;a target process setting unit for previously setting a test target process among the processes confined by the process monitoring unit;a file generation time change monitoring unit for monitoring if the target process set by the target process setting unit requests to change a file generation time;a file generation time change preventing unit for preventing a change in the file generation time of the target process when the target process requests to change the file generation time;and a malicious process detecting unit for determining that a child process of the target process set by the target process setting unit is a malicious process if the child process generates a file within a predetermined reference time.
  2. 5
    The apparatus according to one of claims 1 to 4, wherein file generation time change preventing unit provides a substitution function stored therein instead of the API called by the target process to prevent the change in the file generation time of the target process.
  3. 6
    The apparatus according to one of claims 1 to 5, wherein the child process is generated by the target process set by the target process setting unit.
  4. 7
    The apparatus according to one of claims 1 to 6, wherein when the malicious process detecting unit determines that the child process is not a malicious process, the target process setting unit sets the child process as a target process.
  5. 8
    A method for detecting a malicious process, comprising:monitoring if a process generated in a computing environment is a child process of a preset target process;and recognizing the generated process as a malicious process when the process monitored, to be the child process generates a file within a predetermined reference time.
  6. 11
    The method according to claims 8, 9 or 10, further comprising monitoring if the generated process calls an Application Program interface (API) required for changing a file generation time and providing a substitution function instead of the API when the generated process is the preset target process.
  7. 12
    The method according to one of claims 8 to 11, further comprising registering the generated process as a target process when the process monitored to be the child process generates the file longer than the predetermined reference file
  8. 13
    The method according to one of claims 8 to 12, further comprising forcibly terminating the process recognized as the malicious process.