FIELD: physics, computer engineering.
SUBSTANCE: invention relates to computer engineering. A method of protecting a non-emulated computer system from malware which is attempting to prevent detection or analysis when executed in an emulated computer system includes the following steps: determining whether to identify an executable file as legitimate; and if not, executing the executable file in a non-emulated computer system while simultaneously indicating to the executable file that it is being executed in an emulated computer system.
EFFECT: improved security of the computer system by "simulating" properties which indicate that a program is running in a virtual environment.
19 cl, 6 dwg
Title | Year | Author | Number |
---|---|---|---|
METHOD OF MAINTAINING DATABASE AND CORRESPONDING SERVER | 2015 |
|
RU2698776C2 |
SYSTEM AND METHOD OF STORAGE OF EMULATOR STATE AND ITS FURTHER RECOVERY | 2013 |
|
RU2553056C2 |
METHOD OF INCREASING RELIABILITY OF DETECTING MALICIOUS SOFTWARE | 2012 |
|
RU2485577C1 |
METHOD FOR COUNTERACTING MALICIOUS SOFTWARE (MALWARE) BY IMITATING TEST ENVIRONMENT | 2020 |
|
RU2748518C1 |
SYSTEM AND METHOD OF DETECTING MALWARE | 2010 |
|
RU2430411C1 |
SYSTEM AND METHOD OF CREATING SOFTWARE DETECTION RECORDS | 2012 |
|
RU2491615C1 |
EMULATOR AND METHOD FOR EMULATION | 2020 |
|
RU2757409C1 |
SYSTEM AND METHOD OF CREATING ANTIVIRUS RECORD | 2018 |
|
RU2697954C2 |
METHOD OF DETECTING UNKNOWN PROGRAMS BY LOAD PROCESS EMULATION | 2011 |
|
RU2472215C1 |
SYSTEM AND METHOD OF PROTECTING CLOUD INFRASTRUCTURE FROM ILLEGAL USE | 2012 |
|
RU2536663C2 |
Authors
Dates
2015-10-20—Published
2011-03-15—Filed