Invention Grant
- Patent Title: Detecting malicious computer code in an executing program module
- Patent Title (中): 检测执行程序模块中的恶意计算机代码
-
Application No.: US13427089Application Date: 2012-03-22
-
Publication No.: US08640243B2Publication Date: 2014-01-28
- Inventor: Philip D. Kaufman
- Applicant: Philip D. Kaufman
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Arthur Samodovitz; David J. Zwick
- Main IPC: G06F21/00
- IPC: G06F21/00

Abstract:
A computer program includes one or more computer program instructions, each computer program instruction being of one or more instruction types. Prior to execution of the computer program instructions, the computer determines respective counts for the instruction type(s) of the computer program instructions. At a time during execution of the computer program instructions, the computer determines respective counts for the instruction type(s) of the computer program instructions. The computer, in response to determining that the count for one of the instruction types determined prior to execution differs a predetermined amount from the count for the same instruction type determined during execution, makes a record that the computer program has an indicia of maliciousness.
Public/Granted literature
- US20130254892A1 DETECTING MALICIOUS COMPUTER CODE IN AN EXECUTING PROGRAM MODULE Public/Granted day:2013-09-26
Information query