Method for inspecting an archive
A method for inspecting an archive, the method comprising the steps of: retrieving information from a header of the archive, such as a compression ratio of one or more files of the archive, the average compression ratio of the archive, an expression of the compression ratio of one or more files of the archive, the size of the archive and the number of files stored within the archive, and employing said information for inspecting the archive.
1 . A method for inspecting an archive, the method comprising the steps of:
retrieving information from a header of said archive; and
employing said information for inspecting said archive.
2 . A method according to claim 1 , wherein said information is selected from a group comprising: a compression ratio of one or more files of said archive, the average compression ratio of said archive, an expression of the compression ratio of one or more files of said archive, the size of said archive, and the number of files stored within said archive.
3 . A method according to claim 1 , wherein said inspecting is carried out by comparing the compression ratio of an executable stored within said archive with a threshold, and indicating that said executable is infected by a virus if said compression ratio is less than said threshold.
4 . A method according to claim 3 , wherein said threshold is about 4 percent.
5 . A method according to claim 1 , wherein said inspecting is carried out by comparing the average compression ratio of said archive with a threshold, and indicating that said executable is infected by a virus if said compression ratio is less than said threshold.
6 . A method according to claim 1 , wherein said inspecting is carried out by comparing the average compression ratio of the executables of said archive with a threshold, and indicating that said executable is infected by a virus if said compression ratio is less than said threshold.
7 . A method according to claim 1 , wherein said inspecting is carried out by:
comparing the compression ratio of an executables of said archive with a threshold;
indicating that said executable is suspected to be infected by a virus if said compression ratio is between a first threshold and a second threshold.
8 . A method according to claim 7 , wherein said first compression ratio is about 4 percent.
9 . A method according to claim 7 , wherein said second compression ratio is about 10 percent.
10 . A method according to claim 7 , further comprising determining if said executable is infected by a virus by additional test(s) thereof.
11 . A method according to claim 10 , wherein said additional test(s) is/are selected from a group comprising: overall compression ratio of said archive is less than a third threshold, number of files stored within said archive is less than a fourth threshold.
12 . A method according to claim 12 , wherein said third threshold is 50 KB.
13 . A method according to claim 12 , wherein said fourth threshold is 3 files.