发明名称 Methods and systems for detection of forged computer files
摘要 In accordance with one or more embodiments of the present invention, a method of determining whether a suspect file is malicious includes the operations parsing the suspect file to determine if the suspect file purports to be a system file, performing at least one of a heuristic and signature analysis on the purported system file to determine if one or more attributes of the purported system file are consistent with the known attributes of a system file, and handling the purported system as a malicious file if the purported system file has at least one attribute that is determined not to be consistent with the attributes of a system file. The suspect file is a purported system file when the suspect file includes at least one characteristic attribute of a system file.
申请公布号 US2007056035(A1) 申请公布日期 2007.03.08
申请号 US20060503099 申请日期 2006.08.11
申请人 COPLEY DREW 发明人 COPLEY DREW
分类号 G06F12/14 主分类号 G06F12/14
代理机构 代理人
主权项
地址