ATE387673T1 - Verfahren und system zur heuristischen erkennung von viren in ausführbarem programmkode - Google Patents
Verfahren und system zur heuristischen erkennung von viren in ausführbarem programmkodeInfo
- Publication number
- ATE387673T1 ATE387673T1 AT03780354T AT03780354T ATE387673T1 AT E387673 T1 ATE387673 T1 AT E387673T1 AT 03780354 T AT03780354 T AT 03780354T AT 03780354 T AT03780354 T AT 03780354T AT E387673 T1 ATE387673 T1 AT E387673T1
- Authority
- AT
- Austria
- Prior art keywords
- program code
- viruses
- executable program
- code
- heuristic detection
- Prior art date
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/562—Static detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L51/00—User-to-user messaging in packet-switching networks, transmitted according to store-and-forward or real-time protocols, e.g. e-mail
- H04L51/21—Monitoring or handling of messages
- H04L51/212—Monitoring or handling of messages using filtering or selective blocking
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- Virology (AREA)
- Health & Medical Sciences (AREA)
- General Physics & Mathematics (AREA)
- General Health & Medical Sciences (AREA)
- Devices For Executing Special Programs (AREA)
- Measuring Or Testing Involving Enzymes Or Micro-Organisms (AREA)
- Debugging And Monitoring (AREA)
- Storage Device Security (AREA)
- Electrotherapy Devices (AREA)
- Selective Calling Equipment (AREA)
- Measuring Pulse, Heart Rate, Blood Pressure Or Blood Flow (AREA)
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
GB0229032A GB2396227B (en) | 2002-12-12 | 2002-12-12 | Method of and system for heuristically detecting viruses in executable code |
Publications (1)
Publication Number | Publication Date |
---|---|
ATE387673T1 true ATE387673T1 (de) | 2008-03-15 |
Family
ID=9949592
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
AT03780354T ATE387673T1 (de) | 2002-12-12 | 2003-12-08 | Verfahren und system zur heuristischen erkennung von viren in ausführbarem programmkode |
Country Status (12)
Country | Link |
---|---|
US (1) | US7519997B2 (de) |
EP (1) | EP1573465B1 (de) |
JP (1) | JP4464832B2 (de) |
AT (1) | ATE387673T1 (de) |
DE (1) | DE60319418T2 (de) |
DK (1) | DK1573465T3 (de) |
ES (1) | ES2302962T3 (de) |
GB (1) | GB2396227B (de) |
HK (1) | HK1074687A1 (de) |
PT (1) | PT1573465E (de) |
SI (1) | SI1573465T1 (de) |
WO (1) | WO2004053663A1 (de) |
Families Citing this family (34)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
AU2003288515A1 (en) * | 2002-12-26 | 2004-07-22 | Commtouch Software Ltd. | Detection and prevention of spam |
GB2400197B (en) * | 2003-04-03 | 2006-04-12 | Messagelabs Ltd | System for and method of detecting malware in macros and executable scripts |
US7984304B1 (en) * | 2004-03-02 | 2011-07-19 | Vmware, Inc. | Dynamic verification of validity of executable code |
US20050283519A1 (en) * | 2004-06-17 | 2005-12-22 | Commtouch Software, Ltd. | Methods and systems for combating spam |
US7694340B2 (en) * | 2004-06-21 | 2010-04-06 | Microsoft Corporation | Anti virus for an item store |
US8037534B2 (en) * | 2005-02-28 | 2011-10-11 | Smith Joseph B | Strategies for ensuring that executable content conforms to predetermined patterns of behavior (“inverse virus checking”) |
US8272058B2 (en) * | 2005-07-29 | 2012-09-18 | Bit 9, Inc. | Centralized timed analysis in a network security system |
US8984636B2 (en) * | 2005-07-29 | 2015-03-17 | Bit9, Inc. | Content extractor and analysis system |
US7895651B2 (en) * | 2005-07-29 | 2011-02-22 | Bit 9, Inc. | Content tracking in a network security system |
US20070028291A1 (en) * | 2005-07-29 | 2007-02-01 | Bit 9, Inc. | Parametric content control in a network security system |
CN100374972C (zh) * | 2005-08-03 | 2008-03-12 | 珠海金山软件股份有限公司 | 一种检测和防御计算机恶意程序的系统和方法 |
GB2430336A (en) * | 2005-09-16 | 2007-03-21 | Jeroen Oostendorp | System which converts, forwards and/or stores messages in accordance with user defined criteria |
US7873833B2 (en) * | 2006-06-29 | 2011-01-18 | Cisco Technology, Inc. | Detection of frequent and dispersed invariants |
US8261344B2 (en) * | 2006-06-30 | 2012-09-04 | Sophos Plc | Method and system for classification of software using characteristics and combinations of such characteristics |
US8365286B2 (en) * | 2006-06-30 | 2013-01-29 | Sophos Plc | Method and system for classification of software using characteristics and combinations of such characteristics |
US20080134333A1 (en) * | 2006-12-04 | 2008-06-05 | Messagelabs Limited | Detecting exploits in electronic objects |
US20090013405A1 (en) * | 2007-07-06 | 2009-01-08 | Messagelabs Limited | Heuristic detection of malicious code |
US9237166B2 (en) * | 2008-05-13 | 2016-01-12 | Rpx Corporation | Internet search engine preventing virus exchange |
US8904536B2 (en) * | 2008-08-28 | 2014-12-02 | AVG Netherlands B.V. | Heuristic method of code analysis |
JP5133192B2 (ja) * | 2008-10-06 | 2013-01-30 | 日本電信電話株式会社 | オリジナルコードの抽出装置、抽出方法、および抽出プログラム |
JP5588781B2 (ja) | 2010-08-10 | 2014-09-10 | 富士通株式会社 | セキュアモジュールおよび情報処理装置 |
CN102110220B (zh) * | 2011-02-14 | 2013-01-23 | 宇龙计算机通信科技(深圳)有限公司 | 一种应用程序监控方法及装置 |
CN103902901B (zh) * | 2013-09-17 | 2017-10-31 | 北京安天网络安全技术有限公司 | 一种基于编译器识别的apt检测方法及系统 |
KR101846757B1 (ko) * | 2013-12-27 | 2018-05-28 | 맥아피, 엘엘씨 | 빈도-기반 평판도 |
US9262296B1 (en) | 2014-01-31 | 2016-02-16 | Cylance Inc. | Static feature extraction from structured files |
RU2606559C1 (ru) * | 2015-10-22 | 2017-01-10 | Акционерное общество "Лаборатория Касперского" | Система и способ оптимизации антивирусной проверки файлов |
KR101947737B1 (ko) * | 2016-12-06 | 2019-02-13 | 서울대학교산학협력단 | 명시적 및 암시적 정보 흐름 추적 방법 및 그 장치 |
US20210133330A1 (en) * | 2019-11-01 | 2021-05-06 | Blackberry Limited | Determining a security score in binary software code |
US11556618B2 (en) * | 2020-02-18 | 2023-01-17 | At&T Intellectual Property I, L.P. | Split ledger software license platform |
US11663113B2 (en) | 2020-02-20 | 2023-05-30 | International Business Machines Corporation | Real time fault localization using combinatorial test design techniques and test case priority selection |
US11307975B2 (en) | 2020-02-20 | 2022-04-19 | International Business Machines Corporation | Machine code analysis for identifying software defects |
US11086768B1 (en) * | 2020-02-20 | 2021-08-10 | International Business Machines Corporation | Identifying false positives in test case failures using combinatorics |
US11176026B2 (en) | 2020-02-20 | 2021-11-16 | International Business Machines Corporation | Assignment of test case priorities based on combinatorial test design model analysis |
US11604740B2 (en) * | 2020-12-01 | 2023-03-14 | Capital One Services, Llc | Obfuscating cryptographic material in memory |
Family Cites Families (7)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US5440723A (en) * | 1993-01-19 | 1995-08-08 | International Business Machines Corporation | Automatic immune system for computers and computer networks |
US5675711A (en) * | 1994-05-13 | 1997-10-07 | International Business Machines Corporation | Adaptive statistical regression and classification of data strings, with application to the generic detection of computer viruses |
US6016546A (en) * | 1997-07-10 | 2000-01-18 | International Business Machines Corporation | Efficient detection of computer viruses and other data traits |
US6357008B1 (en) * | 1997-09-23 | 2002-03-12 | Symantec Corporation | Dynamic heuristic method for detecting computer viruses using decryption exploration and evaluation phases |
US6971019B1 (en) * | 2000-03-14 | 2005-11-29 | Symantec Corporation | Histogram-based virus detection |
US7069589B2 (en) | 2000-07-14 | 2006-06-27 | Computer Associates Think, Inc.. | Detection of a class of viral code |
US7502939B2 (en) * | 2001-04-19 | 2009-03-10 | Cybersoft, Inc. | Software virus detection methods and apparatus |
-
2002
- 2002-12-12 GB GB0229032A patent/GB2396227B/en not_active Expired - Fee Related
-
2003
- 2003-12-08 DK DK03780354T patent/DK1573465T3/da active
- 2003-12-08 DE DE60319418T patent/DE60319418T2/de not_active Expired - Lifetime
- 2003-12-08 US US10/500,953 patent/US7519997B2/en active Active
- 2003-12-08 EP EP03780354A patent/EP1573465B1/de not_active Expired - Lifetime
- 2003-12-08 ES ES03780354T patent/ES2302962T3/es not_active Expired - Lifetime
- 2003-12-08 PT PT03780354T patent/PT1573465E/pt unknown
- 2003-12-08 JP JP2004558798A patent/JP4464832B2/ja not_active Expired - Fee Related
- 2003-12-08 AT AT03780354T patent/ATE387673T1/de not_active IP Right Cessation
- 2003-12-08 SI SI200331219T patent/SI1573465T1/sl unknown
- 2003-12-08 WO PCT/GB2003/005328 patent/WO2004053663A1/en active IP Right Grant
-
2005
- 2005-09-21 HK HK05108251A patent/HK1074687A1/xx not_active IP Right Cessation
Also Published As
Publication number | Publication date |
---|---|
DK1573465T3 (da) | 2008-06-23 |
US20050022016A1 (en) | 2005-01-27 |
WO2004053663A1 (en) | 2004-06-24 |
EP1573465B1 (de) | 2008-02-27 |
ES2302962T3 (es) | 2008-08-01 |
HK1074687A1 (en) | 2005-11-18 |
PT1573465E (pt) | 2008-04-16 |
GB2396227B (en) | 2006-02-08 |
AU2003288435A1 (en) | 2004-06-30 |
US7519997B2 (en) | 2009-04-14 |
DE60319418D1 (de) | 2008-04-10 |
GB0229032D0 (en) | 2003-01-15 |
JP2006510089A (ja) | 2006-03-23 |
DE60319418T2 (de) | 2009-02-19 |
JP4464832B2 (ja) | 2010-05-19 |
GB2396227A (en) | 2004-06-16 |
SI1573465T1 (sl) | 2008-08-31 |
EP1573465A1 (de) | 2005-09-14 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
ATE387673T1 (de) | Verfahren und system zur heuristischen erkennung von viren in ausführbarem programmkode | |
WO2004097604A3 (en) | A method of, and system for, heuristically detective viruses in executable code | |
DE60128227D1 (de) | Verfahren und system zur e-mailverarbeitung | |
DE69609980D1 (de) | Verfahren und system zur erkennung von polymorphen viren | |
WO2006019726A3 (en) | System and method for detecting computer virus | |
NO984004D0 (no) | FremgangsmÕte for pÕvisning av influensavirus og forbindelser for anvendelse ved fremgangsmÕten | |
WO2006009880A3 (en) | Identifying virally infected and vaccinated organisms | |
EP1501010A3 (de) | Beschreibungssprache für eine erweiterbare Compiler- und Werkzeug-Infrastruktur | |
BR9712592A (pt) | Processo para gerar um clone infeccioso, ácido nucléico recombinante, molécula do mesmo, vìrus de rna modificado, célula infectada com o mesmo, vacina, proteìna e/ou antìgeno, e, ensaio diagnóstico | |
DE69818232D1 (de) | Verfahren und system zur verhinderung des herunterladens und ausführens von ausführbaren objekten | |
ATE460473T1 (de) | Immortalisierte entezelllinien zur viruserzeugung | |
ATE466321T1 (de) | Antivirus-manifest für dokumentausdruck | |
EP1316873A3 (de) | Vorrichtung und Verfahren zum Identifizieren von infizierten Programmbefehlen | |
WO2004017183A3 (en) | Method of, and system for, heuristically detecting viruses in executable code | |
WO2004097602A3 (en) | A method of, and system for, heuristically determining that an unknown file is harmless by using traffic heuristics | |
RU2007138951A (ru) | ЗАЩИТА КОМПЬЮТЕРА, ПРЕДОСТАВЛЯЮЩЕГО УСЛУГУ Web, ОТ ВРЕДОНОСНЫХ ПРОГРАММНЫХ СРЕДСТВ | |
ATE385259T1 (de) | Verfahren zum nachweis von influenza a/b-viren in speichel | |
ATE437393T1 (de) | Verfahren und vorrichtung zur bereitstellung eines entkoppelten leistungsverwaltungszustands | |
EA201390856A1 (ru) | Инактивация вирусов с применением улучшенного способа растворитель-детергент | |
EA201071086A1 (ru) | Усовершенствованный способ получения вакцинных антигенов вируса гриппа | |
DE69434117D1 (de) | Verfahren zur typisierung von hepatitis c viren und dafür zu verwendende reagenzien | |
DE69936337D1 (de) | Verfahren zur entwicklung von einem hiv impfstoff | |
CN102799824B (zh) | 一种针对具有数字签名信息的病毒文件的防御方法及系统 | |
EA200701870A1 (ru) | Пептид, происходящий из вируса гепатита с | |
ATE428448T1 (de) | Verfahren zur dna-dekontamination |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
UEP | Publication of translation of european patent specification |
Ref document number: 1573465 Country of ref document: EP |
|
REN | Ceased due to non-payment of the annual fee |