CN100576135C - 用于病毒扫描的方法和系统 - Google Patents
用于病毒扫描的方法和系统 Download PDFInfo
- Publication number
- CN100576135C CN100576135C CN200510108886A CN200510108886A CN100576135C CN 100576135 C CN100576135 C CN 100576135C CN 200510108886 A CN200510108886 A CN 200510108886A CN 200510108886 A CN200510108886 A CN 200510108886A CN 100576135 C CN100576135 C CN 100576135C
- Authority
- CN
- China
- Prior art keywords
- file
- mark
- document
- malware
- virus
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Expired - Fee Related
Links
- 241000700605 Viruses Species 0.000 title claims abstract description 53
- 238000000034 method Methods 0.000 title claims abstract description 43
- 230000002596 correlated effect Effects 0.000 claims abstract description 31
- 230000009385 viral infection Effects 0.000 claims abstract description 12
- 208000036142 Viral infection Diseases 0.000 claims description 7
- 230000006378 damage Effects 0.000 claims description 5
- 238000001514 detection method Methods 0.000 claims 6
- 230000002155 anti-virotic effect Effects 0.000 abstract description 51
- 230000008569 process Effects 0.000 abstract description 14
- 230000008595 infiltration Effects 0.000 abstract description 2
- 238000001764 infiltration Methods 0.000 abstract description 2
- 230000006854 communication Effects 0.000 description 7
- 230000015654 memory Effects 0.000 description 7
- 238000004891 communication Methods 0.000 description 6
- 238000010586 diagram Methods 0.000 description 6
- 238000005516 engineering process Methods 0.000 description 5
- 230000003612 virological effect Effects 0.000 description 3
- 230000009471 action Effects 0.000 description 2
- 230000008859 change Effects 0.000 description 2
- 238000004590 computer program Methods 0.000 description 2
- 230000006870 function Effects 0.000 description 2
- 238000007726 management method Methods 0.000 description 2
- 238000012545 processing Methods 0.000 description 2
- 238000012795 verification Methods 0.000 description 2
- 238000004458 analytical method Methods 0.000 description 1
- 230000000845 anti-microbial effect Effects 0.000 description 1
- 239000004599 antimicrobial Substances 0.000 description 1
- 230000005540 biological transmission Effects 0.000 description 1
- 230000015572 biosynthetic process Effects 0.000 description 1
- 238000013500 data storage Methods 0.000 description 1
- 230000007423 decrease Effects 0.000 description 1
- 230000001934 delay Effects 0.000 description 1
- 230000003993 interaction Effects 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000002093 peripheral effect Effects 0.000 description 1
- 230000004044 response Effects 0.000 description 1
- 230000000630 rising effect Effects 0.000 description 1
- 230000003068 static effect Effects 0.000 description 1
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F15/00—Digital computers in general; Data processing equipment in general
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/562—Static detection
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F17/00—Digital computing or data processing equipment or methods, specially adapted for specific functions
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Computer Hardware Design (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Virology (AREA)
- Mathematical Physics (AREA)
- Databases & Information Systems (AREA)
- Data Mining & Analysis (AREA)
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
- Storage Device Security (AREA)
- Glass Compositions (AREA)
- Coloring (AREA)
- Dental Preparations (AREA)
- Pharmaceuticals Containing Other Organic And Inorganic Compounds (AREA)
- Measuring Or Testing Involving Enzymes Or Micro-Organisms (AREA)
Abstract
Description
Claims (12)
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
US10/976,567 | 2004-10-29 | ||
US10/976,567 US20060095964A1 (en) | 2004-10-29 | 2004-10-29 | Document stamping antivirus manifest |
Publications (2)
Publication Number | Publication Date |
---|---|
CN1766779A CN1766779A (zh) | 2006-05-03 |
CN100576135C true CN100576135C (zh) | 2009-12-30 |
Family
ID=35809596
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN200510108886A Expired - Fee Related CN100576135C (zh) | 2004-10-29 | 2005-09-29 | 用于病毒扫描的方法和系统 |
Country Status (7)
Country | Link |
---|---|
US (1) | US20060095964A1 (zh) |
EP (1) | EP1653318B1 (zh) |
JP (1) | JP4828193B2 (zh) |
KR (1) | KR20060051168A (zh) |
CN (1) | CN100576135C (zh) |
AT (1) | ATE466321T1 (zh) |
DE (1) | DE602005020889D1 (zh) |
Families Citing this family (17)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US7917955B1 (en) * | 2005-01-14 | 2011-03-29 | Mcafee, Inc. | System, method and computer program product for context-driven behavioral heuristics |
US8321910B1 (en) * | 2005-01-21 | 2012-11-27 | Trend Micro, Inc. | Determining the source of malware |
US20080134326A2 (en) * | 2005-09-13 | 2008-06-05 | Cloudmark, Inc. | Signature for Executable Code |
US8161556B2 (en) * | 2008-12-17 | 2012-04-17 | Symantec Corporation | Context-aware real-time computer-protection systems and methods |
US20100191784A1 (en) * | 2009-01-29 | 2010-07-29 | Sobel William E | Extending Secure Management of File Attribute Information to Virtual Hard Disks |
US8732473B2 (en) * | 2010-06-01 | 2014-05-20 | Microsoft Corporation | Claim based content reputation service |
CN103425927A (zh) * | 2012-05-16 | 2013-12-04 | 腾讯科技(深圳)有限公司 | 计算机文档病毒清除装置及清除方法 |
CN102694801B (zh) * | 2012-05-21 | 2015-08-05 | 华为技术有限公司 | 病毒检测方法、装置以及防火墙设备 |
US9715325B1 (en) | 2012-06-21 | 2017-07-25 | Open Text Corporation | Activity stream based interaction |
CN102984134B (zh) * | 2012-11-12 | 2015-11-25 | 北京奇虎科技有限公司 | 安全防御系统 |
WO2014082599A1 (zh) * | 2012-11-30 | 2014-06-05 | 北京奇虎科技有限公司 | 用于恶意程序查杀的扫描设备、云端管理设备及方法和系统 |
CN103034808B (zh) * | 2012-11-30 | 2015-10-14 | 北京奇虎科技有限公司 | 扫描方法、设备和系统以及云端管理方法和设备 |
CN103092687B (zh) * | 2012-12-26 | 2017-10-20 | 上海斐讯数据通信技术有限公司 | 一种应用程序管理装置和方法 |
CN106570398A (zh) * | 2016-09-09 | 2017-04-19 | 哈尔滨安天科技股份有限公司 | 一种基于结构特性的恶意代码启发式检测方法及系统 |
CN106709346B (zh) * | 2016-11-25 | 2019-08-06 | 腾讯科技(深圳)有限公司 | 文件处理方法及装置 |
CN111414615B (zh) * | 2020-03-27 | 2023-01-20 | 河南经贸职业学院 | 一种基于计算机网络的安全监控系统 |
US11526609B1 (en) * | 2021-11-18 | 2022-12-13 | Uab 360 It | System and method for recent file malware scanning |
Family Cites Families (19)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US5649095A (en) * | 1992-03-30 | 1997-07-15 | Cozza; Paul D. | Method and apparatus for detecting computer viruses through the use of a scan information cache |
US5572590A (en) * | 1994-04-12 | 1996-11-05 | International Business Machines Corporation | Discrimination of malicious changes to digital information using multiple signatures |
US5809138A (en) * | 1994-07-25 | 1998-09-15 | Netz Computing Ltd. | Method for protecting storage media against computer virus infection |
US5826013A (en) * | 1995-09-28 | 1998-10-20 | Symantec Corporation | Polymorphic virus detection module |
US5951698A (en) * | 1996-10-02 | 1999-09-14 | Trend Micro, Incorporated | System, apparatus and method for the detection and removal of viruses in macros |
JP3293760B2 (ja) * | 1997-05-27 | 2002-06-17 | 株式会社エヌイーシー情報システムズ | 改ざん検知機能付きコンピュータシステム |
GB2353372B (en) * | 1999-12-24 | 2001-08-22 | F Secure Oyj | Remote computer virus scanning |
US6763466B1 (en) * | 2000-01-11 | 2004-07-13 | Networks Associates Technology, Inc. | Fast virus scanning |
US6735700B1 (en) * | 2000-01-11 | 2004-05-11 | Network Associates Technology, Inc. | Fast virus scanning using session stamping |
US6973577B1 (en) * | 2000-05-26 | 2005-12-06 | Mcafee, Inc. | System and method for dynamically detecting computer viruses through associative behavioral analysis of runtime state |
US7043757B2 (en) * | 2001-05-22 | 2006-05-09 | Mci, Llc | System and method for malicious code detection |
US7363506B2 (en) * | 2002-01-30 | 2008-04-22 | Cybersoft, Inc. | Software virus detection methods, apparatus and articles of manufacture |
US7290282B1 (en) * | 2002-04-08 | 2007-10-30 | Symantec Corporation | Reducing false positive computer virus detections |
US7367056B1 (en) * | 2002-06-04 | 2008-04-29 | Symantec Corporation | Countering malicious code infections to computer files that have been infected more than once |
GB0214943D0 (en) * | 2002-06-28 | 2002-08-07 | Bitarts Ltd | Computer program protection |
US7478431B1 (en) * | 2002-08-02 | 2009-01-13 | Symantec Corporation | Heuristic detection of computer viruses |
US7337471B2 (en) * | 2002-10-07 | 2008-02-26 | Symantec Corporation | Selective detection of malicious computer code |
JP3979285B2 (ja) * | 2002-12-17 | 2007-09-19 | 株式会社日立製作所 | 情報処理システム |
US7287281B1 (en) * | 2003-06-17 | 2007-10-23 | Symantec Corporation | Send blocking system and method |
-
2004
- 2004-10-29 US US10/976,567 patent/US20060095964A1/en not_active Abandoned
-
2005
- 2005-09-09 KR KR1020050084221A patent/KR20060051168A/ko active IP Right Grant
- 2005-09-29 CN CN200510108886A patent/CN100576135C/zh not_active Expired - Fee Related
- 2005-09-29 JP JP2005284423A patent/JP4828193B2/ja not_active Expired - Fee Related
- 2005-10-18 DE DE602005020889T patent/DE602005020889D1/de active Active
- 2005-10-18 EP EP05109680A patent/EP1653318B1/en not_active Not-in-force
- 2005-10-18 AT AT05109680T patent/ATE466321T1/de not_active IP Right Cessation
Also Published As
Publication number | Publication date |
---|---|
EP1653318A3 (en) | 2008-01-16 |
CN1766779A (zh) | 2006-05-03 |
EP1653318B1 (en) | 2010-04-28 |
DE602005020889D1 (de) | 2010-06-10 |
JP4828193B2 (ja) | 2011-11-30 |
EP1653318A2 (en) | 2006-05-03 |
US20060095964A1 (en) | 2006-05-04 |
ATE466321T1 (de) | 2010-05-15 |
KR20060051168A (ko) | 2006-05-19 |
JP2006127498A (ja) | 2006-05-18 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN100576135C (zh) | 用于病毒扫描的方法和系统 | |
RU2610254C2 (ru) | Система и способ определения измененных веб-страниц | |
JP4880674B2 (ja) | ウェブサービスを提供するコンピュータをマルウェアから保護する方法 | |
RU2638710C1 (ru) | Способы обнаружения вредоносных элементов веб-страниц | |
US9544329B2 (en) | Client/server security by an intermediary executing instructions received from a server and rendering client application instructions | |
US9356954B2 (en) | Intercepting and supervising calls to transformed operations and objects | |
JP6304833B2 (ja) | マルウェア定義パッケージサイズを縮小するためのテレメトリの使用 | |
US8356354B2 (en) | Silent-mode signature testing in anti-malware processing | |
RU2444056C1 (ru) | Система и способ ускорения решения проблем за счет накопления статистической информации | |
CN1924863B (zh) | 在远程计算机上运行为因特网访问而配置的软件的方法和系统 | |
RU2637477C1 (ru) | Система и способ обнаружения фишинговых веб-страниц | |
EP1970835A1 (en) | Method and apparatus for secure web browsing | |
EP3567504A1 (en) | A framework for coordination between endpoint security and network security services | |
US20140090054A1 (en) | System and Method for Detecting Anomalies in Electronic Documents | |
US20140283078A1 (en) | Scanning and filtering of hosted content | |
US9558356B2 (en) | Data driven system for responding to security vulnerability | |
KR101586048B1 (ko) | 불법 어플리케이션 차단 시스템 및 서버, 이를 위한 통신 단말기 및 불법 어플리케이션 차단 방법과 기록매체 | |
JP2012088803A (ja) | 悪性ウェブコード判別システム、悪性ウェブコード判別方法および悪性ウェブコード判別用プログラム | |
RU2634168C1 (ru) | Система и способ блокирования доступа к защищаемым приложениям | |
JP2019194832A (ja) | ウェブリソースの変更を検出するシステムおよび方法 | |
CN108052842A (zh) | 签名数据的存储、验证方法及装置 | |
JP6998099B1 (ja) | アクセスリクエストの不正を検知する方法 | |
CN114969727A (zh) | 基于区块链的攻击行为识别方法、装置和设备 | |
CN114499968A (zh) | 一种xss攻击检测方法及装置 | |
TW202217598A (zh) | 遠端網頁掃描系統及其方法 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
C14 | Grant of patent or utility model | ||
GR01 | Patent grant | ||
ASS | Succession or assignment of patent right |
Owner name: MICROSOFT TECHNOLOGY LICENSING LLC Free format text: FORMER OWNER: MICROSOFT CORP. Effective date: 20150430 |
|
C41 | Transfer of patent application or patent right or utility model | ||
TR01 | Transfer of patent right |
Effective date of registration: 20150430 Address after: Washington State Patentee after: Micro soft technique license Co., Ltd Address before: Washington State Patentee before: Microsoft Corp. |
|
CF01 | Termination of patent right due to non-payment of annual fee | ||
CF01 | Termination of patent right due to non-payment of annual fee |
Granted publication date: 20091230 Termination date: 20170929 |