发明名称 Computer immune system and method for detecting unwanted code in a P-code or partially compiled native-code program executing within a virtual machine
摘要 An automated analysis system identifies the presence of malicious P-code or N-code programs in a manner that limits the possibility of the malicious code infecting a target computer. The target computer system initializes an analytical virtual P-code engine (AVPE). As initialized, the AVPE comprises software simulating the functionality of a P-code or intermediate language engine as well as machine language facilities simulating the P-code library routines that allow the execution of N-code programs. The AVPE executes a target program so that the target program does not interact with the target computer. The AVPE analyzes the behavior of the target program to identify occurrence of malicious code behavior and to indicate in a behavior pattern the occurrence of malicious code behavior. The AVPE is terminated at the end of the analysis process, thereby removing from the computer system the copy of the target program that was contained within the AVPE.
申请公布号 US7370360(B2) 申请公布日期 2008.05.06
申请号 US20020145592 申请日期 2002.05.13
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 VAN DER MADE PETER A. J.
分类号 G06F11/00;G06F21/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址