发明名称 DETECTION OF SPYWARE THREATS WITHIN VIRTUAL MACHINE
摘要 A system analyzes content accessed at a network site to determine whether it is malicious. The system employs a tool able to identify spyware that is piggy-backed on executable files (such as software downloads) and is able to detect drive-by download attacks that install software on the victim's computer when a page is rendered by a browser program. The tool uses a virtual machine (VM) to sandbox and analyze potentially malicious content. By installing and running executable files within a clean VM environment, commercial anti-spyware tools can be employed to determine whether a specific executable contains piggy-backed spyware. By visiting a Web page with an unmodified browser inside a clean VM environment, predefined triggers, such as the installation of a new library, or the creation of a new process, can be used to determine whether the page mounts a drive-by download attack.
申请公布号 US2013014259(A1) 申请公布日期 2013.01.10
申请号 US201213488222 申请日期 2012.06.04
申请人 UNIVERSITY OF WASHINGTON THROUGH ITS CENTER FOR COMMERCIALIZATION;GRIBBLE STEVEN;LEVY HENRY;MOSHCHUK ALEXANDER;BRAGIN TANYA 发明人 GRIBBLE STEVEN;LEVY HENRY;MOSHCHUK ALEXANDER;BRAGIN TANYA
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址