Invention Grant
US07664754B2 Method of, and system for, heuristically detecting viruses in executable code 失效
在可执行代码中启发式检测病毒的方法和系统

  • Patent Title: Method of, and system for, heuristically detecting viruses in executable code
  • Patent Title (中): 在可执行代码中启发式检测病毒的方法和系统
  • Application No.: US10500954
    Application Date: 2004-03-08
  • Publication No.: US07664754B2
    Publication Date: 2010-02-16
  • Inventor: Alexander Shipp
  • Applicant: Alexander Shipp
  • Applicant Address: US CA Mountain View
  • Assignee: Symantec Corporation
  • Current Assignee: Symantec Corporation
  • Current Assignee Address: US CA Mountain View
  • Agency: Gunnison, McKay & Hodgson, L.L.P.
  • Agent Philip J. McKay
  • Priority: GB0309464.6 20030425
  • International Application: PCT/GB2004/000997 WO 20040308
  • International Announcement: WO2004/097604 WO 20041111
  • Main IPC: G06F17/30
  • IPC: G06F17/30
Method of, and system for, heuristically detecting viruses in executable code
Abstract:
In an anti-virus scanning system for computer files being transferred between computers, the number of files requiring detailed scanning is first reduced by identifying files which are instances of programs which are known and deemed to be safe. This is done by reference to a database of known executables which records characteristics which can be used as the basis for identifying a file as an unchanged instance of a known executable. Secondly, these characteristics can then also be used to identify files which are changed instances of known executables. These are extremely suspicious, since the most likely cause of change is infection by a file infecting virus, so these files are classed as likely to be malware.
Information query
Patent Agency Ranking
0/0