International Journal of Information Technology & Computer Science ( IJITCS )

Existing antivirus products (AVs) rely on detecting virus signatures which do not provide a full solution to the problems associated with these viruses. The use of logic formulae to model the behaviour of viruses is one of the most encouraging recent developments in virus research, which provides alternatives to classic virus detection methods. In this paper, an implementation of a behaviour-based virus detection will be provided. This paper explains how the formal language can be used to represent computer viruses by means of their behaviours. It also explains which tools should be used to extract system calls that represent the steps of virus behaviour at both user and kernel levels .

: Computer viruses; virus detection; signature-based; behaviour-based; Interval Temporal Logic

