发明名称 METHOD FOR DETECTING THE FILE WITH FRAUD NAME AND APPARATUS THEREOF
摘要 PURPOSE: A method for detecting a file with an extension of a fraud name and an apparatus thereof are provided to compare an extension of a file with a real extension, thereby classifying a dangerous file with a malicious code to block if the extension is matched with the real extension. CONSTITUTION: A file header structure database(140) is composed of an extension and header information. A control module(150) extracts a display extension from a file name of a file and extracts header information corresponding to the display extension from the file header structure database. When the header information does not accord with contents of the file, the control module decides the extension of the file as a forged file extension.
申请公布号 KR20100005518(A) 申请公布日期 2010.01.15
申请号 KR20080065590 申请日期 2008.07.07
申请人 AHNLAB, INC. 发明人 KIM, JI HOON
分类号 G06F21/00;G06F9/06;G06F17/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址