首页> 外国专利> System and method for preventing malware evasion

System and method for preventing malware evasion

机译:防止恶意软件规避的系统和方法

摘要

A computerized method that assists in preventing malware from evading detection through analysis of the virtual hardware components operating within a malware detection system is described. First, a virtual machine (VM) is provisioned in accordance with a guest image, which includes a guest operating system and one or more virtual hardware component. The virtual hardware component including an identifier, and the guest operating system includes a software driver that controls access to the virtual hardware component and features the identifier of the virtual hardware component. Responsive to processing an object within the VM and issuance of a request for an identifier of a hardware component, the identifier of the first virtualized hardware component (virtualization of the hardware component) is received. The first identifier of the first virtual hardware component being an identifier substituted for a prior identifier of the first virtual hardware component before creation of the guest image.
机译:描述了一种计算机方法,该方法通过分析在恶意软件检测系统内运行的虚拟硬件组件来帮助防止恶意软件逃避检测。首先,根据来宾映像配置虚拟机(VM),该映像包括来宾操作系统和一个或多个虚拟硬件组件。包括标识符的虚拟硬件组件,以及客户操作系统包括控制对虚拟硬件组件的访问并以虚拟硬件组件的标识符为特征的软件驱动程序。响应于处理VM内的对象并发出对硬件组件的标识符的请求,接收第一虚拟化硬件组件的标识符(硬件组件的虚拟化)。第一虚拟硬件组件的第一标识符是在创建访客映像之前替换第一虚拟硬件组件的先前标识符的标识符。

著录项

  • 公开/公告号US10747872B1

    专利类型

  • 公开/公告日2020-08-18

    原文格式PDF

  • 申请/专利权人 FIREEYE INC.;

    申请/专利号US201715717547

  • 发明设计人 PHUNG-TE HA;MIN LI;

    申请日2017-09-27

  • 分类号G06F9/455;G06F21/53;G06F9/4401;G06F21/54;H04L29/06;G06F13/42;

  • 国家 US

  • 入库时间 2022-08-21 11:31:09

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号