会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 2. 发明授权
    • Priority-based virus scanning with priorities based at least in part on heuristic prediction of scanning risk
    • 基于优先级的病毒扫描,至少部分基于扫描风险的启发式预测
    • US06851058B1
    • 2005-02-01
    • US09625534
    • 2000-07-26
    • Paul Gartside
    • Paul Gartside
    • G06F1/24G06F21/00
    • G06F21/56G06F21/577
    • Anti-virus scanners can be deliberately disabled, inadvertently disabled, or simply slowed down to a point where the scanner becomes ineffective and the primary function of the scanning host device is disrupted when a suitably complex file is received by the scanning system for scanning. Archive files pose particular problems for scanners, since archives may contain very complex data structures, and require time consuming analysis. Virus scanners typically scan each element of an archive. Some virus scanners decompress each archive component for scanning. Virus developers have taken advantage of this scanning approach by creating complex archives designed to overwhelm a scanner, leaving a system unprotected or in a denial of service state. To counter such measures, when an archive (or other file) is passed to a scanner, various heuristics are applied to the archive so as to determine a risk-based scanning priority for the archive. Priorities can include normal priority, low priority for archives having suspicious characteristics, and discard without scanning for archives appearing to be constructed so as to overwhelm a scanner. Normal priority scans can occur immediately, while low priority scans can be relegated to only occurring while the scanning system is otherwise idle.
    • 防病毒扫描器可以故意禁用,无意中禁用,或简单地减慢到扫描仪无效的点,并且扫描主机设备的主要功能在扫描系统接收到适当复杂的文件进行扫描时会中断。 归档文件对扫描仪造成特殊问题,因为归档可能包含非常复杂的数据结构,并且需要耗时的分析。 病毒扫描程序通常扫描存档的每个元素。 一些病毒扫描程序解压每个归档组件进行扫描。 病毒开发人员利用这种扫描方法,创建了复杂的档案,旨在压倒扫描仪,使系统无保护或处于拒绝服务状态。 为了应对这种措施,当将档案(或其他文件)传递到扫描仪时,将各种启发式应用于存档,以便确定归档的基于风险的扫描优先级。 优先级可以包括正常优先级,具有可疑特征的档案的优先级低,并且丢弃而不扫描似乎被构造的档案以压倒扫描器。 正常优先级扫描可以立即发生,而低优先级扫描可以降级到仅在扫描系统空闲时才发生。