14-07-2016 дата публикации
Номер: KR101639675B1
Автор:
KIM, EUI TAK,
HAN, KWAN SEOK,
KIM, JI HUN,
PARK, DAE SEONG,
SONG, JAE HOON,
JUN, DAE IL,
JI, HYUN JUN
The present invention relates to an apparatus for diagnosing whether a file is infected by a polymorphic virus, which includes a parsing and classification unit (110) that parses binary codes of a diagnosis target file into instructions and classifies the instructions for items, a first stop condition database (160) that finds information on a virus section made by a polymorphic virus and stores a first stop condition that is a condition for obtaining decoding information for decoding an encoded part, a comparison unit (120) that compares an item and the first stop condition and obtains decoding information from the coinciding first stop condition, a decoding unit (140) that decodes an encoded part of the virus section by using the decoding information and obtaining a decoding file, and a control unit (150) that compares the decoding file with a virus pattern that is registered in the polymorphic virus diagnosing apparatus and diagnosing that the diagnosis target file is infected by the ...
Подробнее