FIELD: physics, computation hardware.
SUBSTANCE: invention relates to antivirus software and hardware, particularly to emulator state retention and its further recovery. File is received for emulation. Check for first-time emulation is executed. Emulator state image is defined including at least the image of emulating system to be loaded in emulator for further file emulation. File is emulated. Emulator state images are created. Note here that every said image comprises at least the image of emulating system. Incorrect file emulation termination is tested. Required emulator state image is selected for continuation of emulation in the case of incorrect file emulation termination. Selected emulator state image is loaded for file emulation continuation.
EFFECT: accelerated emulation.
14 cl, 6 dwg
Title | Year | Author | Number |
---|---|---|---|
EMULATOR AND METHOD FOR EMULATION | 2020 |
|
RU2757409C1 |
METHOD OF EMULATING SYSTEM FUNCTION CALLS FOR EVADING EMULATION COUNTERMEASURES | 2012 |
|
RU2514141C1 |
METHOD OF DETECTING UNKNOWN PROGRAMS BY LOAD PROCESS EMULATION | 2011 |
|
RU2472215C1 |
METHOD OF MAINTAINING DATABASE AND CORRESPONDING SERVER | 2015 |
|
RU2698776C2 |
METHOD OF PROTECTING COMPUTER SYSTEM FROM MALWARE | 2011 |
|
RU2566329C2 |
SYSTEM AND METHOD FOR AUTOMATIC PROCESSING OF SOFTWARE SYSTEM ERRORS | 2012 |
|
RU2521265C2 |
METHOD FOR ENHANCEMENT OF OPERATIONAL EFFICIENCY OF HARDWARE ACCELERATION OF APPLICATION EMULATION | 2012 |
|
RU2514142C1 |
SYSTEM AND METHOD FOR MODIFICATION OF LIMITED EXECUTION ENVIRONMENT FOR LAUNCHING, EXECUTING, AND CHECKING APPLICATION FOR MALICIOUS CODE | 2021 |
|
RU2784701C1 |
METHOD OF DETECTING MALICIOUS EXECUTABLES, CONTAINING INTERPRETER, BY COMBINING EMULATORS | 2015 |
|
RU2622627C2 |
SYSTEM AND METHOD OF DETECTING MALWARE | 2010 |
|
RU2430411C1 |
Authors
Dates
2015-06-10—Published
2013-10-24—Filed