首页> 外国专利> System and method of analysis of files for maliciousness in a virtual machine

System and method of analysis of files for maliciousness in a virtual machine

机译:分析虚拟机中的文件是否存在恶意的系统和方法

摘要

Disclosed are systems and methods of analysis of files for maliciousness in a virtual machine. An exemplary method comprises: opening and executing a file by a processor in a virtual machine; intercepting an event arising in the process of execution of a thread of a process created upon opening of the file; halting the execution of the thread; reading the context of the processor on which the thread is being executed; comparing the context of the processor with one or more rules; and based on the results of the comparison, performing at least one of: recognizing the file as being malicious; halting the execution of the process created upon opening of the file; changing the context of the processor; and waiting for the next intercepted event.
机译:公开了分析文件在虚拟机中的恶意的系统和方法。一种示例性方法包括:由虚拟机中的处理器打开并执行文件;以及拦截在打开文件时创建的进程的线程的执行过程中发生的事件;停止执行线程;读取正在其上执行线程的处理器的上下文;将处理器的上下文与一个或多个规则进行比较;根据比较结果,执行以下至少一项:识别文件为恶意文件;停止执行打开文件时创建的过程;更改处理器的上下文;并等待下一个被拦截的事件。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号