首页> 外国专利> System and method for analyzing a file for malware in a virtual machine

System and method for analyzing a file for malware in a virtual machine

机译:用于在虚拟机中分析文件中的恶意软件的系统和方法

摘要

Disclosed are systems and methods for analysis of files for maliciousness and determining an action. An exemplary method comprises: opening a file, by a processor, in a virtual machine, intercepting an event arising in an execution of a thread of a process created upon opening of the file, determining, a context of the processor on which the thread is being executed, the determination including reading register values of the processor and a stack, comparing the context with rules that check: a behavior of the thread of the process, a changing, by the thread, of attributes of the file, and an access of the thread to the Internet, and based on a result of the comparison, performing at least one of: recognizing the file as being malicious, halting the execution of the thread, changing the context of the processor, and waiting for a next intercepted event.
机译:公开了用于分析文件的恶意和确定动作的系统和方法。一种示例性方法包括:由处理器在虚拟机中打开文件,拦截在打开文件时创建的进程的线程的执行中发生的事件,确定线程所在的处理器的上下文。在执行过程中,确定过程包括读取处理器和堆栈的寄存器值,将上下文与检查以下规则的规则进行比较:进程线程的行为,线程对文件属性的更改以及对文件属性的访问。连接到Internet的线程,并根据比较的结果,执行以下至少一项操作:识别文件为恶意文件,中止线程的执行,更改处理器的上下文以及等待下一个被拦截的事件。

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号