发明名称 SYSTEM AND METHOD FOR DETECTION OF MALWARE
摘要 <p>A method of automatically identifying malware may include receiving, by an expert system knowledge base, an assembly language sequence from a binary file, identifying an instruction sequence from the received assembly language sequence, and classifying, by the expert system knowledge base, the instruction sequence as threatening, non-threatening or non-classifiable by applying one or more rules of the expert system knowledge base to the instruction sequence. If the instruction sequence is classified as threatening, information may be transmitted to a code analysis component and a user may be notified that the binary file includes malware. The information may include one or more of the following: the instruction sequence, a label comprising an indication that the instruction sequence is threatening, and a request that one or more other assembly language sequences from the binary file be searched for at least a portion of the instruction sequence.</p>
申请公布号 WO2010025453(A1) 申请公布日期 2010.03.04
申请号 WO2009US55524 申请日期 2009.08.31
申请人 AVG TECHNOLOGIES CZ, S.R.O.;HICKS, RYAN 发明人 HICKS, RYAN
分类号 G06F11/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址