发明名称 Detection of decryption to identify encrypted virus
摘要 A method of detecting decryption of encrypted viral code is provided. Executable code in a subject file is emulated by a code emulator. A memory monitor monitors memory access information supplied by the emulator. A memory area that is read during emulation of an instruction in the code is flagged. Modification to the flagged memory area which was read is determined. The memory monitor determines whether a memory region that is contiguous with the modified memory area, and then updates the memory region to encompass the modified memory area. The memory monitor also determines whether the updated memory region is larger than a predetermined size to trigger viral detection. The detection method may be embodied in a computer system, in a computer program (or some unit of code) stored on a computer readable medium, such as a floppy disk, CD, DVD, etc., and/or transmitted via a network, such as the Internet, or another transmission medium.
申请公布号 US7350235(B2) 申请公布日期 2008.03.25
申请号 US20010905533 申请日期 2001.07.14
申请人 COMPUTER ASSOCIATES THINK, INC. 发明人 JORDAN MYLES
分类号 G06F11/30;G06F12/14;G08B23/00;H04L9/32 主分类号 G06F11/30
代理机构 代理人
主权项
地址