发明名称 Detection of viral code using emulation of operating system functions
摘要 A method and apparatus for detecting viral code that uses calls to an operating system to damage computer systems, computers and/or computer files is provided. The apparatus comprises a CPU emulator, a memory manager component and a monitor component. An artificial memory region spanning one or more components of the operating system is created by the memory manager component. Execution of computer executable code in a subject file is emulated by the CPU emulator. An attempt by the emulated computer executable code to access the artificial memory region is detected by the monitor component. The apparatus optionally may comprise an auxiliary component and an analyzer component. The auxiliary component determines an operating system call that the emulated computer executable code attempted to access. The analyzer component monitors the operating system call to determine whether the computer executable code is viral.
申请公布号 US8341743(B2) 申请公布日期 2012.12.25
申请号 US20010905532 申请日期 2001.07.14
申请人 ROGERS ANTONY JOHN;YANN TREVOR;JORDAN MYLES;CA, INC. 发明人 ROGERS ANTONY JOHN;YANN TREVOR;JORDAN MYLES
分类号 H04L29/06;G06F21/00 主分类号 H04L29/06
代理机构 代理人
主权项
地址