发明名称 System and Method for Emulation-based Detection of Malicious Code with Unmet Operating System or Architecture Dependencies
摘要 System, method and media are shown for detecting potentially malicious code by iteratively emulating potentially malicious code, that involve, for each offset of a memory image, emulating execution of an instruction at the offset on a first platform and, if execution fails, determining whether the instruction at the offset has relevance to at least a second platform and, if so, emulating execution of the instruction at the offset on the second platform. If execution succeeds, it involves checking the behavior of the executing code for suspect behavior, and identifying the executing code as malicious code if suspect behavior is detected. Refinements involve applying this process to also determine aspects of information related to the target of any discovered code, malicious or otherwise.
申请公布号 US2016283716(A1) 申请公布日期 2016.09.29
申请号 US201615082970 申请日期 2016.03.28
申请人 Leviathan, Inc. 发明人 Momot Falcon
分类号 G06F21/56 主分类号 G06F21/56
代理机构 代理人
主权项 1. A method for detecting potentially malicious code by iteratively emulating potentially malicious code, the method comprising the steps of: for each offset of a memory image: emulating execution of an instruction at the offset on a first platform;if execution fails, determining whether the instruction at the offset has relevance to at least a second platform and, if so, emulating execution of the instruction at the offset on the second platform;if execution succeeds, checking the behavior of the executing code for suspect behavior; andidentifying the executing code as malicious code if suspect behavior is detected.
地址 Seattle WA US
您可能感兴趣的专利