发明名称 METHODS AND SYSTEMS FOR MALWARE DETECTION BASED ON ENVIRONMENT-DEPENDENT BEHAVIOR
摘要 The present disclosure is directed to methods and systems for malware detection based on environment-dependent behavior. Generally, an analysis environment is used to determine how input collected from an execution environment is used by suspicious software. The methods and systems described identify use of environmental information to decide between execution paths leading to malicious behavior or benign activity. In one aspect, one embodiment of the invention relates to a method comprising monitoring execution of suspect computer instructions; recognizing access by the instructions of an item of environmental information; identifying a plurality of execution paths in the instructions dependant on a branch in the instructions based on a value of the accessed item of environmental information; and determining that a first execution path results in benign behavior and that a second execution path results in malicious behavior. The method comprises classifying the computer instructions as evasive malware responsive to the determination.
申请公布号 US2014317745(A1) 申请公布日期 2014.10.23
申请号 US201313866980 申请日期 2013.04.19
申请人 Lastline, Inc. 发明人 Kolbitsch Clemens;Comparetti Paolo Milani;Cavedon Ludovico
分类号 G06F21/56 主分类号 G06F21/56
代理机构 代理人
主权项 1) A method of classifying malicious computer code, the method comprising: monitoring, by one or more computing processors, execution of a computer program comprising suspicious computer code; recognizing access by the computer program of an item of environmental information; identifying a plurality of execution paths in the computer program dependant on a branch in the computer program based on a value of the accessed item of environmental information; determining that a first execution path in the plurality of execution paths results in benign behavior and that a second execution path in the plurality of execution paths results in malicious behavior; classifying the computer program as evasive malware responsive to the determining.
地址 US