Invention Grant
- Patent Title: Detection of spyware threats within virtual machine
- Patent Title (中): 检测虚拟机中的间谍软件威胁
-
Application No.: US13488222Application Date: 2012-06-04
-
Publication No.: US09043913B2Publication Date: 2015-05-26
- Inventor: Steven Gribble , Henry Levy , Alexander Moshchuk , Tanya Bragin
- Applicant: Steven Gribble , Henry Levy , Alexander Moshchuk , Tanya Bragin
- Applicant Address: US WA Seattle
- Assignee: University of Washington through its Center for Commercialization
- Current Assignee: University of Washington through its Center for Commercialization
- Current Assignee Address: US WA Seattle
- Agency: Perkins Coie LLP
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F21/53 ; G06F21/56 ; G06F21/55 ; H04L29/06

Abstract:
A system analyzes content accessed at a network site to determine whether it is malicious. The system employs a tool able to identify spyware that is piggy-backed on executable files (such as software downloads) and is able to detect “drive-by download” attacks that install software on the victim's computer when a page is rendered by a browser program. The tool uses a virtual machine (VM) to sandbox and analyze potentially malicious content. By installing and running executable files within a clean VM environment, commercial anti-spyware tools can be employed to determine whether a specific executable contains piggy-backed spyware. By visiting a Web page with an unmodified browser inside a clean VM environment, predefined “triggers,” such as the installation of a new library, or the creation of a new process, can be used to determine whether the page mounts a drive-by download attack.
Public/Granted literature
- US20130014259A1 DETECTION OF SPYWARE THREATS WITHIN VIRTUAL MACHINE Public/Granted day:2013-01-10
Information query