Nova Patents
IL160757A

Virus detection system

Abstract

A method of curing an encrypted computer virus present in a computer system includes analyzing encrypted data to determine at least one most frequently occurring encrypted byte in the encrypted data, calculating an encryption key based on the most frequently occurring encrypted byte and a corresponding expected original byte of original data and decrypting the encrypted data using the encryption key to restore the encrypted data to original data.

IL160757A, drawing sheet 1
Sheet 1 of 7

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

21 claims: 3 independent, 18 dependent

  1. 1
    comprising:scanning the computer system for a computer virus: determining whether encrypted data is to be decrypted in order to cure the computer virus detected in the computer system;analyzing the encrypted data to determine at least one most frequently occurring encrypted byte in the encrypted data, when it is determined that the encrypted data is to be decrypted;confirming that the most frequently occurring encrypted byte is a dominant encrypted byte where the dominant encrypted byte is statistically dominant among other bytes of the encrypted data;calculating an encryption key based on the dominant encrypted byte and a corresponding expected original byte of original data;and decrypting the encrypted data using the encryption key to restore the encrypted data to original data present in the computer system prior to encryption by the computer virus.
  2. 4
    The method of Claim 2, wherein the step of applying additional processing is applied when the scanning step fails to detect the computer virus.
  3. 10
    A system for detecting and curing a computer virus in a computer system comprising:a scanning device adapted to scan the computer system for a computer virus;a decryption control device adapted to determine whether decryption of encrypted data in the computer system is to be performed after the computer virus is detected;an encrypted byte processing device adapted to analyze the encrypted data to determine at least one most frequently occurring encrypted byte in the encrypted data when it is determined that the encrypted data is to be decrypted;a dominant byte controller adapted to determine whether the most frequently occurring encrypted byte is a dominant encrypted byte, where a dominant encrypted byte is statistically dominant in the encrypted data;an encryption key calculating device adapted to calculating an encryption key based on the dominant encrypted byte and a corresponding expected original byte of original data;and DAL01:971007.1 a decrypting device adapted to decrypt each byte of encrypted data based on the encryption key to restore the encrypted data to original data present in the computer system prior to encryption by the computer virus.
  4. 21
    A program storage medium, readable by a computer system, embodying computer executable code, comprising:code for scanning the computer system for a computer virus;code for determining whether encrypted data is to be decrypted in order to cure the computer virus detected in the computer system;code for analyzing the encrypted data to determine at least one most frequently occurring encrypted byte in the encrypted data, when it is determined that the encrypted data is to be decrypted;code for confirming that the most frequently occurring encrypted byte is a dominant encrypted byte where the dominant encrypted byte is statistically dominant among other bytes of the encrypted data;code for calculating an encryption key based on the dominant encrypted byte and a corresponding expected original byte of original data;and code for decrypting the encrypted data using the encryption key to restore the encrypted data to original data present in the computer system prior to encryption by the computer virus.