Invention Grant
- Patent Title: System and method of generically detecting the presence of emulated environments
- Patent Title (中): 一般地检测模拟环境的存在的系统和方法
-
Application No.: US11834891Application Date: 2007-08-07
-
Publication No.: US08307429B2Publication Date: 2012-11-06
- Inventor: Richard Ford , William Allen , Gerald Marin
- Applicant: Richard Ford , William Allen , Gerald Marin
- Applicant Address: US FL Melbourne
- Assignee: Florida Institute of Technology
- Current Assignee: Florida Institute of Technology
- Current Assignee Address: US FL Melbourne
- Agency: IP Strategies
- Main IPC: G06F11/00
- IPC: G06F11/00

Abstract:
A method of determining that protected software is running in a virtualized environment includes obtaining a set of baseline measurements of system call timings in native operating system environments. Statistical thresholds are established based on the baseline measurements such that there is a predetermined probability that protected software running in a native environment will experience system call durations that exceed the thresholds. The protected software is analyzed and instructions are incorporated within the software such that particular system calls, demonstrated to be differentiating using the set of baseline measurements and the threshold analysis, are executed during the normal running of the protected software. The incorporated instructions are used to estimate the parameter values that are to be compared with the established statistical thresholds. Repeated comparisons of the estimates obtained during the normal running of the protected software are executed to determine whether the software is running in a virtualized environment.
Public/Granted literature
- US20080147353A1 System and Method of Generically Detecting the Presence of Emulated Environments Public/Granted day:2008-06-19
Information query