发明名称 SYSTEM AND METHOD FOR DETECTING MULTI-COMPONENT MALWARE
摘要 Malicious behavior of a computer program is detected using an emulation engine, an event detector and an event analyzer. The emulation engine includes a system emulator configured to emulate, in an isolated computer environment, at least a part of a computer system and a program emulator configured to emulate in the isolated computer environment execution of the computer program, including execution of a plurality of executable components of the computer program, such as execution processes and threads. The event detector is configured to monitor events being generated by two or more of the executable components. The event analyzer is configured to determine, substantially in real time, based at least on one or more events generated by each of two or more of the plurality of executable components whether or not the computer program exhibits malicious behavior, wherein individually one or more of the plurality of executable components may exhibit benign behavior.
申请公布号 US2009126016(A1) 申请公布日期 2009.05.14
申请号 US20070866302 申请日期 2007.10.02
申请人 SOBKO ANDREY;PAVLYUSHCHIK MIKHAIL A 发明人 SOBKO ANDREY;PAVLYUSHCHIK MIKHAIL A.
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址