发明名称 Automated sample creation of polymorphic and non-polymorphic macro viruses
摘要 <p>Disclosed is a system and method for automatically generating at least one instance of a computer macro virus that is native to or associated with an application. The method includes steps of (a) providing a suspect virus sample; and (b) replicating the suspect virus sample onto a least one goat file, using at least one of simulated user input or interprocess communication commands for exercising the goat file through the application, to generate an infected goat file. A further step can be executed of (c) replicating the infected goat file onto a least one further goat file, using at least one of simulated user input, such as keystrokes, mouse clicks and the like, or interprocess communication commands, to generate an additional instance of an infected goat file. The step of providing includes a step of determining attributes of the suspect virus sample, and the steps of exercising employ simulated user input or interprocess communication commands that are selected based at least in part on the determined attributes. As a parallel process the steps of exercising include steps of detecting an occurrence of a window, such as a pop-up window that is opened by one of the application or the macro virus; and using at least one of simulated user input or interprocess communication command(s) for closing the opened window. In this manner the replication process is not halted by a window that requires input from a user. &lt;IMAGE&gt;</p>
申请公布号 EP0918285(A2) 申请公布日期 1999.05.26
申请号 EP19980309016 申请日期 1998.11.04
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 BOULAY, JEAN-MICHEL YANN;PETRILLO, AUGUST T.;SWIMMER, MORTON GREGORY
分类号 G06F21/22;G06F1/00;G06F21/00;(IPC1-7):G06F11/00 主分类号 G06F21/22
代理机构 代理人
主权项
地址