Invention Grant
- Patent Title: Deactivating evasive malware
-
Application No.: US16694185Application Date: 2019-11-25
-
Publication No.: US11144642B2Publication Date: 2021-10-12
- Inventor: Zhongshu Gu , Heqing Huang , Jiyong Jang , Dhilung Hang Kirat , Xiaokui Shu , Marc P. Stoecklin , Jialong Zhang
- Applicant: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Applicant Address: US NY Armonk
- Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Current Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Current Assignee Address: US NY Armonk
- Agent Edward P. Li
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/56 ; G06F8/61 ; G06F16/22 ; G06F21/53

Abstract:
A computer-implemented method, a computer program product, and a computer system. The computer system installs and configures a virtual imitating resource in the computer system, wherein the virtual imitating resource imitates a set of resources in the computer system. Installing and configuring the virtual imitating resource includes modifying respective values of an installed version of the virtual imitating resource for an environment of the computer system, determining whether the virtual imitating resource is a static imitating resource or a dynamic imitating resource, and comparing a call graph of the evasive malware with patterns of dynamic imitating resources on a database. The computer system returns a response from an appropriate element of the virtual imitating resource, in response to a call from the evasive malware to a real computing resource, return, by the computer system.
Public/Granted literature
- US20200089879A1 DEACTIVATING EVASIVE MALWARE Public/Granted day:2020-03-19
Information query