Program detection method, device and program analyzing method
A program detection and program technology, applied in computer security devices, instruments, electrical digital data processing, etc., can solve problems such as complexity, system resource consumption, misjudgment, etc.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
example 1
[0062] Example 1: Assume that on the windows platform, there is a virus virus1 with a system file specially deleted (c:\windows\regedit.exe), the function to be called by virus1 is:
[0063] SOCKET(DEL(PATH(FILENAME(regedit.exe)))),
[0064] ,
[0065] Valid functions for virus1 .
example 2
[0066] Example 2: Suppose virus virus2 instruction code:
[0067] A1, A2, A3, A4, A5, A6, A7, A8, A9, A10, A11, A12, A13, A14, A15...An
[0068] Instructions: A2, A3, A5, A8, A9, A11, A12, and A15 correspond to the logical functions:
[0069] ,
[0070] ,
[0071] Then, A2, A3, A5, A8, A9, A11, A12, A15 are effective instruction codes of virus2, and the remaining codes are non-important function codes or useless codes.
example 3
[0072] Example 3: Suppose the running process of the virus virus3 is:
[0073] The first step is to use the FILENAME() function to determine that the file to be deleted is regedit.exe;
[0074] In the second step, use the PATH() function to determine that the logical path of regedit.exe is c:\windows\regedit.exe;
[0075] The third step is to use the DEL() function to delete c:\windows\regedit.exe.
[0076] The function to be called by the virus virus3 to complete the above three steps is:
[0077] DEL(PATH(FILENAME(regedit.exe))).
[0078] The behavior of virus virus3 is:
[0079] Behavior 1: Determine that the file to be deleted is regedit.exe;
[0080] Behavior 2: Determine the logical path of regedit.exe is c:\windows\regedit.exe;
[0081] Behavior 3: Delete c:\windows\regedit.exe.
[0082] Then, behavior 1→result 1=file regedit.exe is determined;
[0083] Behavior 2→Result 2=the logical path of file regedit.exe is determined;
[0084] Action 3 → Result 3 = The fil...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com