发明名称 FORGERY DETECTION USING ENTROPY MODELING
摘要 <p>In accordance with one or more embodiments of the present invention, a method of determining a suspect computer file is malicious includes parsing a suspect file to extract a byte code sequence, modeling the extracted byte code sequence using at least one entropy modeling test where each modeling test provides an entropy result based on the modeling of the extracted byte code sequence, comparing each entropy result to a table of entropy results to determine a probability value, and summing the probability values to determine a likelihood the byte code sequence is malicious.</p>
申请公布号 WO2007078981(A2) 申请公布日期 2007.07.12
申请号 WO2006US48760 申请日期 2006.12.22
申请人 EEYE DIGITAL SECURITY;COPLEY, DREW 发明人 COPLEY, DREW
分类号 H03M7/38 主分类号 H03M7/38
代理机构 代理人
主权项
地址