Polymorphic virus detection module

Number of patents in Portfolio can not be more than 2000

United States of America Patent

PATENT NO 5696822
SERIAL NO

08535340

Stats

ATTORNEY / AGENT: (SPONSORED)

Importance

Loading Importance Indicators... loading....

Abstract

See full text

A Polymorphic Anti-Virus Module (PAM) (200) comprises a CPU emulator (210) for emulating the target program, a virus signature scanning module (250) for scanning decrypted virus code, and an emulation control module (220), including a static exclusion module (230), a dynamic exclusion module (240), instruction/interrupt usage profiles (224) for the mutation engines (162) of the known polymorphic viruses (150), size and target file types (226) for these viruses, and a table (228) having an entry for each known polymorphic virus (150). Prior to emulation, the static exclusion module (230) examines the gross characteristics of the target file for attributes that are inconsistent with the size/type data (226), and excludes polymorphic viruses (150) from the list (228) accordingly. During emulation, the dynamic exclusion module (240) compares fetched instructions with the instruction/interrupt usage profiles (224) to determine when emulation has proceeded to a point where at least some code from the decrypted static virus body (160) may be scanned for virus signatures.

Loading the Abstract Image... loading....

First Claim

See full text

Family

Loading Family data... loading....

Patent Owner(s)

Patent OwnerAddress
NORTONLIFELOCK INC60 E RIO SALADO PKWY SUITE 1000 TEMPE AS 85281

International Classification(s)

Inventor(s)

Inventor Name Address # of filed Patents Total Citations
Nachenberg, Carey Northridge, CA 52 2271

Cited Art Landscape

Load Citation

Patent Citation Ranking

Forward Cite Landscape

Load Citation