发明名称 Method for detecting infection of software programs by memory resident software viruses
摘要 A method for detecting the infection of executable computer software programs by memory resident computer software virus programs is provided. The invented method comprises comparing an initial state of an executable program to a final state of the program. If the final state of the program is different than the initial state, then the method generates an alarm signal to inform a user that the program has been modified by a virus and is infected. Particularly, as a program is called into memory, that state of the program is marked as the initial state. When execution of the program is completed, that state of the program is marked as the final state. Alternatively, at the moment when processing of the program commences, that state of the program is marked as the final state of the program. The method compares the final and initial states to determine if the two states match. If the two states are the same, then it is confirmed that the program was not modified and is not infected. If it is determined that the two states are different, then the method generates an alarm signal to inform the user that the program is infected. Additionally, if the final state does not match the initial state, a known backup and restore technique can be invoked by the method for restoring the infected program to its initial state.
申请公布号 US5822517(A) 申请公布日期 1998.10.13
申请号 US19960631917 申请日期 1996.04.15
申请人 DOTAN, EYAL 发明人 DOTAN, EYAL
分类号 G06F1/00;G06F21/00;(IPC1-7):H04L9/00;H04K1/00 主分类号 G06F1/00
代理机构 代理人
主权项
地址