首页> 外国专利> Computer immune system and method for detecting unwanted code in a P-code or partially compiled native-code program executing within a virtual machine

Computer immune system and method for detecting unwanted code in a P-code or partially compiled native-code program executing within a virtual machine

机译:用于检测在虚拟机中执行的P代码或部分编译的本机代码程序中不需要的代码的计算机免疫系统和方法

摘要

An automated analysis system identifies the presence of malicious P-code or N-code programs in a manner that limits the possibility of the malicious code infecting a target computer. The target computer system initializes an analytical virtual P-code engine (AVPE). As initialized, the AVPE comprises software simulating the functionality of a P-code or intermediate language engine as well as machine language facilities simulating the P-code library routines that allow the execution of N-code programs. The AVPE executes a target program so that the target program does not interact with the target computer. The AVPE analyzes the behavior of the target program to identify occurrence of malicious code behavior and to indicate in a behavior pattern the occurrence of malicious code behavior. The AVPE is terminated at the end of the analysis process, thereby removing from the computer system the copy of the target program that was contained within the AVPE.
机译:自动化分析系统以限制恶意代码感染目标计算机的可能性的方式识别恶意P代码或N代码程序的存在。目标计算机系统初始化分析虚拟P代码引擎(AVPE)。初始化后,AVPE包括模拟P代码或中间语言引擎功能的软件,以及模拟允许执行N代码程序的P代码库例程的机器语言工具。 AVPE执行目标程序,以便目标程序不与目标计算机交互。 AVPE分析目标程序的行为,以识别恶意代码行为的发生,并以行为模式指示恶意代码行为的发生。 AVPE在分析过程结束时终止,从而从计算机系统中删除了AVPE中包含的目标程序的副本。

著录项

  • 公开/公告号US7900258B2

    专利类型

  • 公开/公告日2011-03-01

    原文格式PDF

  • 申请/专利权人 PETER A. J. VAN DER MADE;

    申请/专利号US20080072295

  • 发明设计人 PETER A. J. VAN DER MADE;

    申请日2008-02-25

  • 分类号G06F11/00;

  • 国家 US

  • 入库时间 2022-08-21 18:08:01

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号