System and Method for Detecting Multi-Component Malware
Abstract
Malicious behavior of a computer program is detected using an emulation engine, an event detector and an event analyzer. The emulation engine includes a system emulator configured to emulate, in an isolated computer environment, at least a part of a computer system and a program emulator configured to emulate in the isolated computer environment execution of the computer program, including execution of a plurality of executable components of the computer program, such as execution processes and threads. The event detector is configured to monitor events being generated by two or more of the executable components. The event analyzer is configured to determine, substantially in real time, based at least on one or more events generated by each of two or more of the plurality of executable components whether or not the computer program exhibits malicious behavior, wherein individually one or more of the plurality of executable components may exhibit benign behavior.
Claims
exact text as granted — not AI-modified1 . A computer-implemented method for detecting malicious behavior of a computer program, comprising:
emulating at least a part of a computer system in an isolated computer environment; emulating execution of the computer program in the isolated computer environment, including emulating execution of a first process and a second process of the computer program; monitoring events being generated by the first process and the second process; and determining, substantially in real time, based on at least one or more event generated by the first process and one or more event generated by the second process whether or not the computer program exhibits malicious behavior.
2 . The computer-implemented method of claim 1 , wherein individually the first process and the second process of a malicious computer program exhibit benign behavior.
3 . The computer-implemented method of claim 2 , wherein emulating execution of a first process and a second process of the computer program includes one or more of:
executing the first and second processes in parallel; and executing the first and second processes sequentially.
4 . The computer-implemented method of claim 3 , wherein determining includes comparing the two or more events generated by the first process and the second process with a pattern of events associated with a malicious program.
5 . The computer-implemented method of claim 4 , further comprising continuing emulating execution of the second process of the computer program even when the first process is terminated.
6 . The computer-implemented method of claim 5 , wherein detecting an event includes detecting at least one of one or more program's system calls and one or more system responses to the program's system calls.
7 . The computer-implemented method of claim 6 , wherein
the first process of the computer program includes one of
a main process of the computer program; and
a child processes of the computer program; and
the second process of the computer program includes one of
a child process of the computer program; and
a grand child process of the computer program.
8 . A system for detecting malicious behavior of a computer program, the system comprising:
a system memory; and a processor configured to emulate in an isolated computer environment of the system memory at least a part of a computer system;
emulate in the isolated computer environment of the system memory execution of the computer program, including execution of a first process and a second process of the computer program;
monitor events being generated by the first process and second process; and determine, substantially in real time, based at least on one or more events generated by the first process and one or more event generated by the second process whether or not the computer program exhibits malicious behavior.
9 . The system of claim 8 , wherein individually the first process and the second process of a malicious computer program exhibit benign behavior.
10 . The system of claim 9 , wherein execution of the first process and the second process of the computer program includes one or more of:
execution of the first and second processes in parallel; and execution of the first and second processes sequentially.
11 . The system of claim 10 , wherein the processor is further configured to compare the two or more events generated by the first process and the second process with a pattern of events associated with a malicious program.
12 . The system of claim 11 , wherein the processor is further configured to continue emulating execution of the second process of the computer program even when the first process is terminated.
13 . The system of claim 12 , wherein the processor is further configured to detect at least one of one or more program's system calls and one or more system responses to the program's system calls.
14 . The system of claim 13 , wherein
the first process of the computer program includes one of
a main process of the computer program; and
a child processes of the computer program; and
the second process of the computer program includes one of
a child process of the computer program; and
a grand child process of the computer program.
15 . A computer-readable medium comprising computer-executable instructions for detecting malicious behavior of a computer program, the computer-executable instructions include:
instructions for emulating in an isolated computer environment at least a part of a computer system; instructions for emulating execution of the computer program in the isolated computer environment, including instructions for emulating execution of a first process and a second process of the computer program; instructions for monitoring events being generated by the first process and second process; and instructions for determining, substantially in real time, based on at least one or more events generated by the first process and one or more events generated by the second process whether or not the computer program exhibits malicious behavior.
16 . The computer-readable medium of claim 15 , wherein individually the first process and the second process of a malicious computer program exhibit benign behavior.
17 . The computer-readable medium of claim 16 , wherein instructions for emulating execution of the first process and the second process includes instruction for one or more of:
executing the first and second processes in parallel; and executing the first and second processes sequentially.
18 . The computer-readable medium of claim 17 , wherein instructions for determining include instructions for comparing the two or more events generated by the first process and the second process with a pattern of events associated with a malicious program.
19 . The computer-readable medium of claim 18 , further including instructions for continuing emulating execution of the second process of the computer program even when the first process is terminated.
20 . The computer-readable medium of claim 15 , wherein
the first process of the computer program includes one of
a main process of the computer program; and
a child processes of the computer program; and
the second process of the computer program includes one of
a child process of the computer program; and
a grand child process of the computer program.Join the waitlist — get patent alerts
Track US2009089878A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.