发明名称 In memory heuristic system and method for detecting viruses
摘要 Characteristics of a call module originating a critical operating system function call are analyzed for indications of suspicious content and a virus threshold counter is incremented appropriately. For example, the memory image to the file image of the call module are compared for indications of suspicious content. If a determination is made that the virus threshold counter exceeds a virus threshold, there is a significant probability that malicious code is executing on the host computer system. Thus, the user of the host computer system and/or an administrator are notified that malicious code is possibly executing on the host computer system.
申请公布号 US7340777(B1) 申请公布日期 2008.03.04
申请号 US20030404167 申请日期 2003.03.31
申请人 SYMANTEC CORPORATION 发明人 SZOR PETER
分类号 H04L9/00 主分类号 H04L9/00
代理机构 代理人
主权项
地址