发明名称 SYSTEM AND METHOD FOR DETECTION OF MALWARE
摘要 <p>A method of automatically identifying malware may include receiving, by an expert system knowledge base, an assembly language sequence from a binary file, identifying an instruction sequence from the received assembly language sequence, and classifying, by the expert system knowledge base, the instruction sequence as threatening, non-threatening or non-classifiable by applying one or more rules of the expert system knowledge base to the instruction sequence. If the instruction sequence is classified as threatening, information may be transmitted to a code analysis component and a user may be notified that the binary file includes malware. The information may include one or more of the following: the instruction sequence, a label comprising an indication that the instruction sequence is threatening, and a request that one or more other assembly language sequences from the binary file be searched for at least a portion of the instruction sequence.</p>
申请公布号 EP2340488(A4) 申请公布日期 2012.07.11
申请号 EP20090810716 申请日期 2009.08.31
申请人 AVG TECHNOLOGIES CZ, S.R.O. 发明人 HICKS, RYAN
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址