Automatic Initiation of Execution Analysis
Abstract
Approaches for transferring control to a bit set. Execution of a bit set upon a host operating system is monitored. A determination is made that the execution of the bit set exhibits a suspicious characteristic. In response, the execution of the bit set on the host operating system is ceased. Then, the bit set is copied into an isolated environment and control to the bit set is transferred within the isolated environment. Thereafter, execution analysis upon the bit set is initiated in the isolated environment. The isolated environment may, but need not, reside on a different physical device than upon which executes the host operating system.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . One or more non-transitory machine-readable storage mediums storing one or more sequences of instructions for initiating execution analysis upon a bit set, which when executed by one or more processors, causes:
monitoring execution of the bit set in a host operating system execution environment; and upon determining that the execution of the bit set exhibits a suspicious characteristic, then (a) ceasing the execution of the bit set in the host operating system execution environment, (b) copying the bit set into an isolated environment and transferring control to the bit set within the isolated environment, and (c) initiating execution analysis upon the bit set in the isolated environment.
2 . The one or more non-transitory machine-readable storage mediums of claim 1 , wherein said suspicious characteristic is creating a new executable bit set or modifying an existing executable bit set in the host operating system execution environment.
3 . The one or more non-transitory machine-readable storage mediums of claim 1 , wherein said suspicious characteristic is loading a new dynamic link library (DLL) file.
4 . The one or more non-transitory machine-readable storage mediums of claim 1 , wherein said monitoring execution of the bit set is only performed upon determining that said bit set is not in either (a) a set of universally known malicious bit sets or (b) a set of locally known virtuous bit sets.
5 . The one or more non-transitory machine-readable storage mediums of claim 1 , wherein said isolated environment resides on a different physical machine than said host operating system execution environment.
6 . The one or more non-transitory machine-readable storage mediums of claim 1 , wherein said host operating system execution environment executes on a device, and wherein execution of the one or more sequences of instructions further cause:
sending information, from said device to a remote location across a network, which describes attributes of said host operating system execution environment; and at said remote location, creating said isolated environment to possess said attributes of said host operating system execution environment.
7 . The one or more non-transitory machine-readable storage mediums of claim 1 , after performing said execution analysis upon the bit set in the isolated environment, updating either a set of universally known malicious bit sets or a set of locally known virtuous bit sets to include said bit set.
8 . The one or more non-transitory machine-readable storage mediums of claim 1 , wherein execution of the one or more sequences of instructions further cause:
updating metadata to prevent the execution analysis to be performed upon the bit set more than once.
9 . An apparatus for initiating execution analysis upon a bit set, comprising:
one or more processors; and one or more non-transitory computer-readable storage mediums storing one or more sequences of instructions, which when executed, cause:
monitoring execution of the bit set in a host operating system execution environment; and
upon determining that the execution of the bit set exhibits a suspicious characteristic, then (a) ceasing the execution of the bit set in the host operating system execution environment, (b) copying the bit set into an isolated environment and transferring control to the bit set within the isolated environment, and (c) initiating execution analysis upon the bit set in the isolated environment.
10 . The apparatus of claim 9 , wherein said suspicious characteristic is creating a new executable bit set or modifying an existing executable bit set in the host operating system execution environment.
11 . The apparatus of claim 9 , wherein said suspicious characteristic is loading a new dynamic link library (DLL) file.
12 . The apparatus of claim 9 , wherein said monitoring execution of the bit set is only performed upon determining that said bit set is not in either (a) a set of universally known malicious bit sets or (b) a set of locally known virtuous bit sets.
13 . The apparatus of claim 9 , wherein said isolated environment resides on a different physical machine than said host operating system execution environment.
14 . The apparatus of claim 9 , wherein said host operating system execution environment executes on a device, and wherein execution of the one or more sequences of instructions further cause:
sending information, from said device to a remote location across a network, which describes attributes of said host operating system execution environment; and at said remote location, creating said isolated environment to possess said attributes of said host operating system execution environment.
15 . The apparatus of claim 9 , after performing said execution analysis upon the bit set in the isolated environment, updating either a set of universally known malicious bit sets or a set of locally known virtuous bit sets to include said bit set.
16 . The apparatus of claim 9 , wherein execution of the one or more sequences of instructions further cause:
updating metadata to prevent the execution analysis to be performed upon the bit set more than once.
17 . A method for initiating execution analysis upon a bit set, comprising:
monitoring execution of the bit set in a host operating system execution environment; and upon determining that the execution of the bit set exhibits a suspicious characteristic, then (a) ceasing the execution of the bit set in the host operating system execution environment, (b) copying the bit set into an isolated environment and transferring control to the bit set within the isolated environment, and (c) initiating execution analysis upon the bit set in the isolated environment.
18 . The method of claim 17 , wherein said monitoring execution of the bit set is only performed upon determining that said bit set is not in either (a) a set of universally known malicious bit sets or (b) a set of locally known virtuous bit sets.
19 . The method of claim 17 , wherein said isolated environment resides on a different physical machine than said host operating system execution environment.
20 . The method of claim 17 , wherein execution of the one or more sequences of instructions further cause:
updating metadata to prevent the execution analysis to be performed upon the bit set more than once.Join the waitlist — get patent alerts
Track US2020218832A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.