发明名称 A method of, and system for, heuristically detective viruses in executable code
摘要 In an anti-virus scanning system for computer files being transferred between computers, the number of files requiring detailed scanning is first reduced by identifying files which are instances of programs which are known and deemed to be safe. This is done by reference to a database of known executables which records characteristics which can be used as the basis for identifying a file as an unchanged instance of a known executable. Secondly, these characteristics can then also be used to identify files which are changed instances of known executables. These are extremely suspicious, since the most likely cause of change is infection by a file infecting virus, so these files are classed as likely to be malware.
申请公布号 AU2004235514(B2) 申请公布日期 2009.10.08
申请号 AU20040235514 申请日期 2004.03.08
申请人 MESSAGELABS LIMITED 发明人 ALEXANDER SHIPP
分类号 G06F21/00;H04L12/58 主分类号 G06F21/00
代理机构 代理人
主权项
地址
您可能感兴趣的专利