20-03-2017 дата публикации
Номер: KR101717941B1
Принадлежит:
AHNLAB, INC.
The present invention relates to a malicious code diagnosis method and an apparatus applied thereto. In detail, a diagnostic value is extracted during each file area in a diagnostic target file in the form of a data stream passes through a buffer, and the malicious code is diagnosed based on the extracted diagnostic value, so that, even if entire contents of the diagnostic target file are not recorded, the malicious code included in the diagnosis target file can be quickly and efficiently diagnosed by using only a minimum amount of resources. In addition, as the malicious code is diagnosed by searching a diagnosis rule in an existing file-based Anti-Virus engine referring to the diagnostic value extracted from the file area, the treatment for the malicious code is unified and reliable diagnosis result is ensured. Further, various types of malicious code can be diagnosed, so the high diagnosis rate can be guaranteed. COPYRIGHT KIPO 2017 (310) Checking unit (320) Extraction unit (330) Diagnosis ...
Подробнее