Method for diagnosing a data-processing installation infected with computer viruses.
Abstract
The method is characterised by using a virus-free program P containing an algorithm, from which a program authentication code PAC = f (P) is formed with the aid of the algorithm at time x = to and is stored together with the program. For testing purposes, this virus-free program is then input as decoy program into the data processing system to be investigated at later times x' = t1, t2, t3,...tn, and started, the program authentication code PAC' produced during this process in each case is compared with the stored program authentication code PAC and an error signal is generated if they are not equal.

Term
Term ended
Projected expiry passed 17 August 2008, 18.1 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
2 claims: 1 independent, 1 dependent
- c-de-00011. A method for diagnosing an infected computer viruses data processing system by means of a test program, marked through the use of an algorithm f containing virus-free program P from which the time x = to use the algorithm, a program authentication code PAC = f is formed (P) and stored along with the program and that this virus-free program for later times x '= t1, t2, t3 ... tn as bait program in which to be examined data processing system introduced and launched, the case respectively resulting program authentication code (PAC' compared) with the stored program authentication code (PAC) and inequality a error signal is generated.
10 paragraphs, as filed
p0001The invention relates to a method for diagnosing an infected computer viruses data processing system according to the features of the preamble of claim 1.
p0002Computer viruses have the ability to infect initially sterile programs, ie change in terms of quality and quantity so that the function and possibly the length of the affected program with those of the original sterile program no longer match. A virus program can occur both as an isolated program as well as in the form of already infected users program. In both cases, it has the ability to create a copy of itself and inject it into another program, which then in turn again occur as a virus and can infect other programs with the result that computer viruses can ultimately spread "snowballed".
p0003Given the damage that can cause an infected program, the timely recognition and detection of such a program is of considerable importance. In practice, these encounters but considerable difficulties because a program, especially as a comprehensive program that is should not be regarded at first glance whether it is infected or not. Comparative tests using a sterile copy of the same program on the basis of a purely visual examination would be possible in principle, but divorced from practical considerations made. The use of the data processing system for program check is ultimately not considered because machine not with absolute certainty can be determined whether a program really does what it should, except that is much less noticeable if a program does something that it does not want.
p0004Incidentally, have such routines, if they could be successfully implemented, only makes sense if they could be repeated. Virus programs can in fact be subject to a special nature, the so-called "trigger" function. The smuggled virus keeps silent then for a predetermined period and is effective only by the so-called trigger, for example, by a program incorporated in the time specified, or by special flags. So if you want to be safe from any "time bombs", the data processing system must be continuously studied in Hinblilck on possibly smuggled and emerging viruses.
p0005The present invention is based on the object to find a method by which a simple and repeatable any review of a data processing system with respect to any existing computer viruses is feasible.
p0006The solution of this object, according to the invention by the characterizing features of claim 1. An advantageous development of the invention is described in claim. 2
p0007The inventive method has the advantage that only a comparison of two codes is required instead of a very complex program comparison. Prerequisite for the functioning of the inventive method is an unequivocally sterile copy of the program, that is, the program must be made on a data processing system, from which it can be assumed with certainty that she was not infected at the time of program preparation. The guarantee that a sterile comparison "Normal" is present, can be added with the easiest one written by the subject himself program in which the subject can be sure that no virus has been planted. The virus found due to a difference between the two codes can then optionally be isolated and studied. From the nature and the virus found action methods may eventually be developed for the disinfection of the plant.
p0008In the following the invention is explained in detail with reference to the drawing. show case<ul><li>1 is a block diagram of an arrangement for generation of a test program,</li><li>2 is a block diagram of an arrangement for carrying out a test run.</li></ul>
p0009The starting point for the novel process is an absolutely virus-free program P, whose particularity is that it contains an algorithm f. According to Figure 1 of this algorithm is generated for the time to from the P program a program authentication code PAC now using, which is saved together with the P program in a storage medium M.
p0010This, test program formed from the virus-free program P and the program authentication code PAC will be introduced according to Figure 2 at later time points t1, t2 ... tn as so-called bait program in which to be examined data processing system, in order to determine whether these data processing system still sterile or is already infested by so-called computer viruses. This, for example, through a present in the data processing system timer T triggered test runs now from so that from the stored test program, ie f is another program authentication code PAC produced 'with the included P program algorithm. Both of these newly formed program authentication code PAC 'and the stored program authentication code PAC a comparator COMP are finally supplied, which generates an error signal in inequality of signals.
1 sheet
Sheet 1
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US7877799B2 | Cited by | United States of America | Applicant |
| US7000117B2 | Cited by | United States of America | Applicant |
| US7467370B2 | Cited by | United States of America | Applicant |
| DE4208777C1 | Cited by | Germany | Search report |
| US7194623B1 | Cited by | United States of America | Applicant |
| WO9213307A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US7076655B2 | Cited by | United States of America | Applicant |
| WO9213307A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO0073904A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US7457951B1 | Cited by | United States of America | Applicant |
| US5544322A | Cited by | United States of America | Search report |
| US5398196A | Cited by | United States of America | Search report |
| US7353531B2 | Cited by | United States of America | Applicant |
| WO0073904A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US3745316A | Cites | United States of America | Search report |
| US4355390A | Cites | United States of America | Search report |
| AU519055A | Cites | Australia | Search report |
4 priority claims, no other members on record
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 3727687 | Germany | – | |
| 3727687 | Germany | A | |
| DE19873727687 | – | – | – |
| 3727687 | – | – | – |
8 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Application deemed to be withdrawnWithdrawn18D | 18D | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWNSTAA | STAA | |
| First examination report despatched17Q | 17Q | |
| Request for examination filed17P | 17P | |
| Designated contracting statesAK | AK | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | |
| Designated contracting statesAK | AK | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI |
Numbers
- Publication
- 0304033
- Publication, DOCDB
- 0304033
- Publication, EPODOC
- EP0304033
- Application
- 881133516
- Application, DOCDB
- 88113351
- Application, EPODOC
- EP19880113351
Titles6
- German
- Verfahren zum Diagnostizieren einer von Computerviren befallenen Datenverarbeitungsanlage
- English
- Method for diagnosing a data-processing installation infected with computer viruses
- French
- Procédé de diagnostic d'une installation de traitement de données atteinte par des virus d'ordinateur
- German
- Verfahren zum Diagnostizieren einer von Computerviren befallenen Datenverarbeitungsanlage.
- English
- Method for diagnosing a data-processing installation infected with computer viruses.
- French
- Procédé de diagnostic d'une installation de traitement de données atteinte par des virus d'ordinateur.
Classification
- CPC, 2
- G06F21/565
- H02P6/06
- IPC, 2
- G06F1 00
- G06F21 56
Designated states11
- Contracting states, 11
- Austria
- Belgium
- Switzerland
- Germany
- Spain
- France
- United Kingdom
- Italy
- Liechtenstein
- Netherlands (Kingdom of the)
- Sweden