FIELD: information technology.
SUBSTANCE: method includes steps of: emulating object execution; recording performed operations in a journal with memory during emulation of object execution; merging said operations with memory into at least one serial set; determining high-level operations that were performed during emulation of object execution on the operations with memory merged into at least one serial set; creating software detection records based on high-level operation information.
EFFECT: improved detection of unknown packers by using detection records created based on information on high-level operations, execution of which said unknown packer is responsible.
12 cl, 4 dwg
Authors
Dates
2013-08-27—Published
2012-02-24—Filed