发明名称 SYSTEMS AND METHODS FOR VIRTUALIZATION AND EMULATION ASSISTED MALWARE DETECTION
摘要 Systems and methods for virtualization and emulation malware enabled detection are described. In some embodiments, a method comprises intercepting an object, instantiating and processing the object in a virtualization environment, tracing operations of the object while processing within the virtualization environment, detecting suspicious behavior associated with the object, instantiating an emulation environment in response to the detected suspicious behavior, processing, recording responses to, and tracing operations of the object within the emulation environment, detecting a divergence between the traced operations of the object within the virtualization environment to the traced operations of the object within the emulation environment, re-instantiating the virtualization environment, providing the recorded response from the emulation environment to the object in the virtualization environment, monitoring the operations of the object within the re-instantiation of the virtualization environment, identifying untrusted actions from the monitored operations, and generating a report regarding the identified untrusted actions of the object.
申请公布号 EP3093762(A1) 申请公布日期 2016.11.16
申请号 EP20160167215 申请日期 2012.11.05
申请人 CYPHORT, INC. 发明人 GOLSHAN, ALI;BINDER, JAMES, S
分类号 G06F11/00;G06F9/455;G06F11/36;G06F21/53;G06F21/55;G06F21/56;H04L29/06 主分类号 G06F11/00
代理机构 代理人
主权项
地址