Information security – Monitoring or scanning of software or data including attack... – Intrusion detection
Reexamination Certificate
2004-01-30
2009-11-17
Zand, Kambiz (Department: 2434)
Information security
Monitoring or scanning of software or data including attack...
Intrusion detection
C713S188000
Reexamination Certificate
active
07620990
ABSTRACT:
A system and method for determining whether a packed executable is malware is presented. In operation, a malware evaluator intercepts incoming data directed to a computer. The malware evaluator evaluates the incoming data to determine whether the incoming data is a packed executable. If the incoming data is a packed executable, the malware evaluator passes the packed executable to an unpacking module. The unpacking module includes a set of unpacker modules for unpacking a packed executable of a particular type. The unpacking module selects an unpacker module according to the type of the packed executable, and executes the selected unpacker module. Executing the unpacker module generates an unpacked executable corresponding to the packed executable. The unpacked executable is returned to the malware evaluator where it is evaluated to determine whether the packed executable is malware.
REFERENCES:
patent: 6594686 (2003-07-01), Edwards et al.
patent: 6968461 (2005-11-01), Lucas et al.
patent: 7203681 (2007-04-01), Arnold et al.
patent: 2002/0035696 (2002-03-01), Thacker
patent: 2003/0014550 (2003-01-01), Fischer et al.
patent: 2003/0023865 (2003-01-01), Cowie et al.
patent: 2003/0110391 (2003-06-01), Wolff et al.
patent: 2003/0115479 (2003-06-01), Edwards et al.
patent: 2005/0132206 (2005-06-01), Palliyil et al.
patent: 2005/0172337 (2005-08-01), Bodorin et al.
patent: 2006/0248582 (2006-11-01), Panjwani et al.
Bodorin Daniel M.
Marinescu Adrian M.
Hailu Teshome
Microsoft Corporation
Workman Nydegger
Zand Kambiz
LandOfFree
System and method for unpacking packed executables for... does not yet have a rating. At this time, there are no reviews or comments for this patent.
If you have personal experience with System and method for unpacking packed executables for..., we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and System and method for unpacking packed executables for... will most certainly appreciate the feedback.
Profile ID: LFUS-PAI-O-4105086