发明名称 Method and apparatus for determination of the non-replicative behavior of a malicious program
摘要 Disclosed is a method, a computer system and a computer readable media product that contains a set of computer executable software instructions for directing the computer system to execute a process for determining a non-replicative behavior of a program that is suspected of containing an undesirable software entity. The process causes execution of the program in at least one known environment and automatically examines the at least one known environment to detect if a change has occurred in the environment as a result of the execution of the program. If a change is detected, the process automatically analyzes the detected change (i.e., the process performs a side effects analysis) to determine if the change resulted from execution of the program or from execution of the undesirable software entity. The process then uses the result of the analysis at least for undoing a detected change that results from execution of the undesirable software entity. The result of the analysis can also be used for informing a user of an anti-virus system of the non-replicative changes made to the environment.
申请公布号 US2003212906(A1) 申请公布日期 2003.11.13
申请号 US20020141896 申请日期 2002.05.08
申请人 ARNOLD WILLIAM C.;CHESS DAVID M.;MORAR JOHN F.;SEGAL ALLA;WHALLEY IAN N.;WHITE STEVE R. 发明人 ARNOLD WILLIAM C.;CHESS DAVID M.;MORAR JOHN F.;SEGAL ALLA;WHALLEY IAN N.;WHITE STEVE R.
分类号 G06F21/00;(IPC1-7):G06F11/30 主分类号 G06F21/00
代理机构 代理人
主权项
地址