发明名称 APPARATUS AND METHOD FOR DETECTING IF VIRUS PROGRAM IS COMPRESSED
摘要 PURPOSE: An apparatus for detecting execution and compression of a malicious code and a method thereof are provided to enhance diagnostic performance for the malicious code by measuring entropy of an executed file. CONSTITUTION: An executable files are collected to be checked whether a malicious code exists or not by an executable file collector(102). An entropy measuring unit(104) calculates an entropy value of the executable files which are collected in the executable file collector. An testing unit(106) for execution and compression compares measured two entropy values of the executable files. The testing unit for execution and compression decides the executable file as an execution and compression file when the measured entropy value is lower than a set value.
申请公布号 KR101033258(B1) 申请公布日期 2011.05.23
申请号 KR20080085080 申请日期 2008.08.29
申请人 发明人
分类号 G06F21/00;G06F9/44;G06F15/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址
您可能感兴趣的专利