发明名称 System and Method for Detection of Malicious Code by Iterative Emulation of Microcode
摘要 Examples of systems, methods and media are shown for iteratively emulating potentially malicious code involving, for each offset of a microarchitecture for the code, emulating a first ring of an operating system, executing a segment of code in the emulated first ring, checking the behavior of the executing code for suspect behavior, and identifying the executing code as malicious code if suspect behavior is detected. Some examples include emulating a second ring of the operating system having a higher level of privilege than the first ring, such that the second ring emulation returns results to the executing code segment, but does not actually perform the functionality in a host platform.
申请公布号 US2016196425(A1) 申请公布日期 2016.07.07
申请号 US201514807330 申请日期 2015.07.23
申请人 Leviathan, Inc. 发明人 Davidov Mikhail;Stach Patrick
分类号 G06F21/53;G06F21/56 主分类号 G06F21/53
代理机构 代理人
主权项 1. A method for iteratively emulating potentially malicious code, the method comprising the steps of: for each offset of a microarchitecture for the code: emulating a first ring of an operating system;executing a segment of code in the emulated first ring;checking the behavior of the executing code for suspect behavior; andidentifying the executing code as malicious code if suspect behavior is detected.
地址 Seattle WA US