摘要 |
PURPOSE: A malignant code inspecting device and a method thereof are provided to improve a diagnosis rate of the Java file by confirming a distrust class and a distrust character string included in class and character string information. CONSTITUTION: A weak point database(116) stores weak points by mapping a distrust class, a distrust character string, and a distrust figure on the weak points. A decoding unit(112) extracts imported class information, character string information, and figure information by decoding a file made by a Java code. A malignant code determination unit(114) confirms a malignant class included in the imported class information based on the weak point database. When the distrust character string is existed in the character string information, the malignant code determination unit determines the file as a malignant file. The decoding unit extracts the figure information from a structure in the file made by the Java code. [Reference numerals] (110) File receiving unit; (112) Decoding unit; (114) Malignant code determination unit; (116) Weak point database; (150) Agent server; |