Abstract: The invention relates to a method for recognizing a piece of malware in a computer memory system, comprising the steps of: providing a master signature comprising a number of byte sequences, producing at least one first signature element, said first signature element comprising a subset of the number of byte sequences in the master signature, and applying the first signature element to data stored in the computer memory system in order to recognize a piece of malware stored in the computer memory system.
Abstract: The invention relates to a method for characterizing a computer program section held in a computer memory system, comprising the steps of breaking down the computer program section into segments, wherein program commands contained in the computer program section are used to define a program flow relationship between the segments, and determining characteristic data which can be associated with the program flow relationship of the segments, wherein the characteristic data are compressed to form a signature which identifies the computer program section.