发明名称 Detection of polymorphic virus code using dataflow analysis
摘要 A method and apparatus for detecting polymorphic viral code in a computer program is provided. The apparatus comprises an emulator, an operational code analyzer and an heuristic analyzer. The emulator emulates a selected number of instructions of the computer program. The operational code analyzer collects and stores information corresponding to operands and operators used in the instructions and the state of registers/flags after each emulated instruction execution. The heuristic analyzer determines a probability that the computer program contains viral code based on an heuristic analysis of register/flag state information supplied by the operational code analyzer.
申请公布号 US7069583(B2) 申请公布日期 2006.06.27
申请号 US20010905341 申请日期 2001.07.14
申请人 COMPUTER ASSOCIATES THINK, INC. 发明人 YANN TREVOR;PETROVSKY OLEG
分类号 H04L9/00;G06F1/00;G06F21/00 主分类号 H04L9/00
代理机构 代理人
主权项
地址