发明名称 Methods for detecting executable code which has been altered
摘要 Methods of detecting executable code which has been altered are provided. Upon an initial loading of an executable code a calculation is performed to generate a score associated with the executable code, the initial score is retained. Subsequently, one or more additional calculations are performed on the executable code to generate subsequent scores. Any subsequent score not matching the initial score indicates the executable code has been varied in some way. If variations have occurred, determinations are made to assess whether the variations correspond to valid conditions, especially valid conditions of a vendor supplying the executable code. If variations do not correspond to valid conditions, the executable code is then partially or completely disabled and optionally unloaded from the operating system within which it resides. Moreover, the vendor may be notified, or other events triggered. Calculations may be performed on the executable code randomly, periodically or other.
申请公布号 US7647639(B2) 申请公布日期 2010.01.12
申请号 US20060355286 申请日期 2006.02.15
申请人 NOVELL, INC. 发明人 TAYLOR NEIL W.
分类号 H04L9/32 主分类号 H04L9/32
代理机构 代理人
主权项
地址