Invention Grant
US08713631B1 System and method for detecting malicious code executed by virtual machine
有权
用于检测由虚拟机执行的恶意代码的系统和方法
- Patent Title: System and method for detecting malicious code executed by virtual machine
- Patent Title (中): 用于检测由虚拟机执行的恶意代码的系统和方法
-
Application No.: US13767391Application Date: 2013-02-14
-
Publication No.: US08713631B1Publication Date: 2014-04-29
- Inventor: Mikhail A. Pavlyushchik
- Applicant: Kaspersky Lab ZAO
- Applicant Address: RU Moscow
- Assignee: Kaspersky Lab ZAO
- Current Assignee: Kaspersky Lab ZAO
- Current Assignee Address: RU Moscow
- Agency: Patterson Thuente Pedersen, PA
- Priority: RU2012156443 20121225
- Main IPC: G06F21/53
- IPC: G06F21/53 ; G06F9/455

Abstract:
Protection against a malicious set of program instructions (e.g., a malicious program) executable by a process virtual machine. The program instructions of process virtual machine are augmented to establish an exception monitoring module within the process virtual machine. When the process virtual machine executes a subject set of program instructions, the exception monitoring module detects a security policy violation exception occurring as a result. In response thereto, the exception monitoring module gathers context information representing circumstances surrounding the occurrence of the exception, and provides the context information for analysis of a presence of malicious code. The exception monitoring module determines, based on a result of the analysis, whether to permit further execution of the subject set of program instructions by the process virtual machine.
Information query