发明名称 Detection of suspicious privileged access to restricted computer resources
摘要 Methods and apparatus for detecting computer viruses that attempt to gain access to restricted computer system resources are provided. The apparatus comprises an emulator component, a monitor component and a detector component. The emulator emulates computer executable code in a subject file. The monitor component monitors emulation of the computer executable code and monitoring a memory state of the computer system for modifications caused by the emulated instructions in the computer executable code. Based on information supplied by the monitor component regarding the emulated code and any modifications of the memory state, the detector component detects an attempt by the emulated code to access one or more of the restricted computer system resources.
申请公布号 US7210040(B2) 申请公布日期 2007.04.24
申请号 US20010905340 申请日期 2001.07.14
申请人 COMPUTER ASSOCIATES THINK, INC. 发明人 JORDAN MYLES
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址