The most important finding about computer virus detection is made by Cohen who says no algorithm exists with the capability of detecting all possible computer viruses, but it might be some embarrassed with today's malicious codes which do not always "infect" other programs again. This paper extends Cohen's impossibility finds to a more generally level to malicious code detection and presents a virtual behavior mechanism in which a behavior detection function can be inserted. If any malicious code detected, it can be recruited as if it never happened, so as not to cause any actual impact to system.
Kristof T. SchüttMarius KloftAlexander BikadorovKonrad Rieck
Jiehui DengDan LiuYue HuZong-Wen Liang