发明名称 Priority-based virus scanning with priorities based at least in part on heuristic prediction of scanning risk
摘要 Anti-virus scanners can be deliberately disabled, inadvertently disabled, or simply slowed down to a point where the scanner becomes ineffective and the primary function of the scanning host device is disrupted when a suitably complex file is received by the scanning system for scanning. Archive files pose particular problems for scanners, since archives may contain very complex data structures, and require time consuming analysis. Virus scanners typically scan each element of an archive. Some virus scanners decompress each archive component for scanning. Virus developers have taken advantage of this scanning approach by creating complex archives designed to overwhelm a scanner, leaving a system unprotected or in a denial of service state. To counter such measures, when an archive (or other file) is passed to a scanner, various heuristics are applied to the archive so as to determine a risk-based scanning priority for the archive. Priorities can include normal priority, low priority for archives having suspicious characteristics, and discard without scanning for archives appearing to be constructed so as to overwhelm a scanner. Normal priority scans can occur immediately, while low priority scans can be relegated to only occurring while the scanning system is otherwise idle.
申请公布号 US6851058(B1) 申请公布日期 2005.02.01
申请号 US20000625534 申请日期 2000.07.26
申请人 NETWORKS ASSOCIATES TECHNOLOGY, INC. 发明人 GARTSIDE PAUL
分类号 G06F1/24;G06F21/00;(IPC1-7):G06F1/24 主分类号 G06F1/24
代理机构 代理人
主权项
地址