发明名称 METHODS AND SYSTEMS FOR MALWARE DETECTION BASED ON ENVIRONMENT-DEPENDENT BEHAVIOR
摘要 The present disclosure is directed to methods and systems for malware detection based on environment-dependent behavior. Generally, an analysis environment is used to determine how input collected from an execution environment is used by suspicious software. The methods and systems described identify use of environmental information to decide between execution paths leading to malicious behavior or benign activity. In one aspect, one embodiment of the invention relates to a method comprising monitoring execution of suspect computer instructions; recognizing access by the instructions of an item of environmental information; identifying a plurality of execution paths in the instructions dependant on a branch in the instructions based on a value of the accessed item of environmental information; and determining that a first execution path results in benign behavior and that a second execution path results in malicious behavior. The method comprises classifying the computer instructions as evasive malware responsive to the determination.
申请公布号 WO2014172064(A1) 申请公布日期 2014.10.23
申请号 WO2014US31443 申请日期 2014.03.21
申请人 LASTLINE, INC. 发明人 KOLBITSCH, CLEMENS;COMPARETTI, PAOLO MILANI;CAVEDON, LUDOVICO
分类号 G06F12/14 主分类号 G06F12/14
代理机构 代理人
主权项
地址