EP1760620A2

Methods and Systems for Detection of Forged Computer Files

Abstract

In accordance with one or more embodiments of the present invention, a method of determining whether a suspect file is malicious includes the operations parsing the suspect file to determine if the suspect file purports to be a system file, performing at least one of a heuristic and signature analysis on the purported system file to determine if one or more attributes of the purported system file are consistent with the known attributes of a system file, and handling the purported system as a malicious file if the purported system file has at least one attribute that is determined not to be consistent with the attributes of a system file. The suspect file is a purported system file when the suspect file includes at least one characteristic attribute of a system file.

EP1760620A2, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Projected expiry passed 15 August 2026, 0.1 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

20 claims: 5 independent, 15 dependent

  1. 1
    A method of determining whether a suspect file is malicious, comprising the operations of:parsing the suspect file to determine if the suspect file purports to be a system file, the suspect file being a purported system file when the suspect file includes at least one characteristic attribute of a system file;performing at least one of a heuristic and signature analysis on the purported system file to determine if one or more attributes of the purported system file are consistent with the known attributes of a system file;and handling the purported system as a malicious file if the purported system file has at least one attribute that is determined not to be consistent with the attributes of a system file.
  2. 9
    The method of any one of claims 1 to 8, wherein handling the purported system as a malicious file comprises at least one of:quarantining the malicious file;and deleting the malicious file.
  3. 10
    A computer readable medium on which is stored a computer program for executing the following instructions:parsing a suspect file to determine if the suspect file purports to be a system file, the suspect file being a purported system file when the suspect file includes at least one characteristic attribute of a system file;performing at least one of a heuristic and signature analysis on the purported system file to determine if one or more attributes of the purported system file are consistent with the known attributes of a system file;and handling the purported system as a malicious file if the purported system file has at least one attribute that is determined not to be consistent with the attributes of a system file.
  4. 11
    A malware resistant computer system, comprising:a processing unit;a removable media interface configured to provide access to a received removable media element;a memory unit;and a computer file system, wherein the processing unit executes a series of operations to detect malware in at least one of the memory unit and the computer file system, the operations comprising: parsing a suspect file to determine if the suspect file purports to be a system file, the suspect file being a purported system file when the suspect file includes at least one characteristic attribute of a system file;performing at least one of a heuristic and signature analysis on the purported system file to determine if one or more attributes of the purported system file are consistent with the known attributes of a system file;and handling the purported system as a malicious file if the purported system file has at least one attribute that is determined not to be consistent with the attributes of a system file.
  5. 12
    A method, comprising:receiving a suspect file;examining the suspect file to determine if the file purports to be a system file;examining the attributes of the purported system file to determine if the attributes are consistent with a system file;and declaring the purported file to be a forgery when the attributes are not consistent with the attributes of a system file.