Invention Grant
US07647639B2 Methods for detecting executable code which has been altered 有权
检测已被更改的可执行代码的方法

  • Patent Title: Methods for detecting executable code which has been altered
  • Patent Title (中): 检测已被更改的可执行代码的方法
  • Application No.: US11355286
    Application Date: 2006-02-15
  • Publication No.: US07647639B2
    Publication Date: 2010-01-12
  • Inventor: Neil W. Taylor
  • Applicant: Neil W. Taylor
  • Applicant Address: US UT Provo
  • Assignee: Novell, Inc.
  • Current Assignee: Novell, Inc.
  • Current Assignee Address: US UT Provo
  • Agency: King & Schickli, PLLC
  • Main IPC: H04L9/32
  • IPC: H04L9/32
Methods for detecting executable code which has been altered
Abstract:
Methods of detecting executable code which has been altered are provided. Upon an initial loading of an executable code a calculation is performed to generate a score associated with the executable code, the initial score is retained. Subsequently, one or more additional calculations are performed on the executable code to generate subsequent scores. Any subsequent score not matching the initial score indicates the executable code has been varied in some way. If variations have occurred, determinations are made to assess whether the variations correspond to valid conditions, especially valid conditions of a vendor supplying the executable code. If variations do not correspond to valid conditions, the executable code is then partially or completely disabled and optionally unloaded from the operating system within which it resides. Moreover, the vendor may be notified, or other events triggered. Calculations may be performed on the executable code randomly, periodically or other.
Public/Granted literature
Information query
Patent Agency Ranking
0/0