U.S. patents available from 1976 to present.
U.S. patent applications available from 2005 to present.

Automated sample creation of polymorphic and non-polymorphic marcro viruses

Patent 6108799 Issued on August 22, 2000. Estimated Expiration Date: Icon_subject March 12, 2018. Estimated Expiration Date is calculated based on simple USPTO term provisions. It does not account for terminal disclaimers, term adjustments, failure to pay maintenance fees, or other factors which might affect the term of a patent.

Patent References

Method and apparatus for detection of computer viruses
Patent #: 5398196
Issued on: 03/14/1995
Inventor: Chambers

Automatic immune system for computers and computer networks
Patent #: 5440723
Issued on: 08/08/1995
Inventor: Arnold, et al.

Methods and apparatus for evaluating and extracting signatures of computer viruses and other undesirable software entities
Patent #: 5452442
Issued on: 09/19/1995
Inventor: Kephart

Automatic analysis of a computer virus structure and means of attachment to its hosts
Patent #: 5485575
Issued on: 01/16/1996
Inventor: Chess, et al.

Discrimination of malicious changes to digital information using multiple signatures
Patent #: 5572590
Issued on: 11/05/1996
Inventor: Chess

Generic disinfection of programs infected with a computer virus
Patent #: 5613002
Issued on: 03/18/1997
Inventor: Kephart, et al.

Polymorphic virus detection module
Patent #: 5826013
Issued on: 10/20/1998
Inventor: Nachenberg

Computer virus trap
Patent #: 5842002
Issued on: 11/24/1998
Inventor: Schnurer, et al.

System, apparatus and method for the detection and removal of viruses in macros
Patent #: 5951698
Issued on: 09/14/1999
Inventor: Chen, et al.

Detection and elimination of macro viruses
Patent #: 5978917
Issued on: 11/02/1999
Inventor: Chi

More ...

Inventors

Application

No. 041493 filed on 03/12/1998

US Classes:

714/38, Of computer software714/26, Artificial intelligence (e.g., diagnostic expert system)717/127Monitoring program execution

Examiners

Primary: Beausoliel, Robert W. Jr.
Assistant: Weir, James G.

Attorney, Agent or Firm

International Classes

G06F 011/00
G06F 013/00

Abstract

Disclosed is a system and method for automatically generating at least one instance of a computer macro virus that is native to or associated with an application. The method includes steps of (a) providing a suspect virus sample; and (b) replicating the suspect virus sample onto a least one goat file, using at least one of simulated user input or interprocess communication commands for exercising the goat file through the application, to generate an infected goat file. A further step can be executed of (c) replicating the infected goat file onto a least one further goat file, using at least one of simulated user input, such as keystrokes, mouse clicks and the like, or interprocess communication commands, to generate an additional instance of an infected goat file. The step of providing includes a step of determining attributes of the suspect virus sample, and the steps of exercising employ simulated user input or interprocess communication commands that are selected based at least in part on the determined attributes. As a parallel process the steps of exercising include steps of detecting an occurrence of a window, such as a pop-up window that is opened by one of the application or the macro virus; and using at least one of simulated user input or interprocess communication command(s) for closing the opened window. In this manner the replication process is not halted by a window that requires input from a user.

Other References

  • Symantec, Understanding Heuristics: Symantec's Bloodhound technology, Sep. 1997, www.symantec.com, pp. 1-14
  • An Immune System for Cyberspace by Jeffrey O. Kephart et al. in IEEE, 1997, pp. 879-884 Biologically Inspired defenses Against Computer Viruses J. Kephart et al, at High Integrity Computing Laboratory at IBM Thomas J. Watson Research Center, Yorktown Heights, NY 10598, pp. 985-996
  • J. O. Kephart et al., "Blueprint for a Computer Immune System", Presented at the Virus Bulleting International Conference in San Fransisco, Oct. 1-3, 1997., 14 Pages,
  • "Method of Rule-Based File, Window, and Messages Processing", IBM Technical Disclosure Bulletin, vol. 38, No. 7, Jul. 1995
  • Vesselin Bontchev, "Possible macro virus attacks and how to prevent them", Computers & Security, vol. 15, No. 7, pp. 596-626, (1996
PatentsPlus Images
Enhanced PDF formats
loading...
PatentsPlus: add to cart
PatentsPlus: add to cartSearch-enhanced full patent PDF image
$9.95more info
PatentsPlus: add to cart
PatentsPlus: add to cartIntelligent turbocharged patent PDFs with marked up images
$16.95more info
 
Sign InRegister
Username  
Password   
forgot password?