发明名称 |
Detection of a class of viral code |
摘要 |
A method and apparatus for detecting a class of viral code are provided. The apparatus comprises an heuristic analyzer and a search component. The heuristic analyzer heuristically analyzes a subject file and generates a set of flags along with statistical information. The search component uses the set of flags with statistical information to perform a search for a scan string and/or a statement type in the subject file. A positive detection alarm is triggered if the scan string and/or statement type is found at least a corresponding predetermined number of times. The heuristic analyzer may be rule-based and comprise an heuristic engine and heuristic rules. The search component also may be rule-based and comprise a search engine and viral code class rules.
|
申请公布号 |
US7069589(B2) |
申请公布日期 |
2006.06.27 |
申请号 |
US20010905342 |
申请日期 |
2001.07.14 |
申请人 |
COMPUTER ASSOCIATES THINK, INC.. |
发明人 |
SCHMALL MARKUS;KWAN TONY |
分类号 |
G06F1/00;G06F21/00 |
主分类号 |
G06F1/00 |
代理机构 |
|
代理人 |
|
主权项 |
|
地址 |
|