[ news_security_news ] Patent Granted To McAfee
SecurityProNews Staff Writer
2004-10-20
Insider Reports RSS Feed
McAfee has been granted U.S. Patent 6,775,780 entitled "Detecting Malicious Software By Analyzing Patterns Of System Calls Generated During Emulation".
The granted patent covers various programs, products and methods for determining whether software is likely to exhibit malicious behavior by analyzing patterns of system calls made during emulation of the software. Emulation of software occurs within an insulated environment, for example, an emulator, within a computer system. The insulated environment protects the computer system from malicious actions of the software while the behavior of the software is examined. Emulation results may be used to determine whether the software is likely to exhibit malicious behavior.
According to a particular example, among many encompassed by the granted patent, a pattern of system calls made to an operating system of a computer system may be recorded during emulation of software. Such pattern of system calls may then be compared against a database containing suspect patterns of system calls. Using results of the foregoing comparison, it may then be determined whether the software is likely to exhibit malicious behavior.
The above process may be continued as necessary to search for behavior that is likely to be malicious. Moreover, termination conditions may be used to halt the above functionality under certain circumstances. Just by way of example, the process may be terminated if a maximum number of instructions are executed during the emulation. Still yet, the process may be terminated if a maximum number of system calls are made during the emulation. Thus, the patented use of software emulation enables improved searching for likely malicious behavior.
"This patent is another example of McAfee's research and development leadership in the security field," said Christopher Bolin, chief technology officer of McAfee, Inc. "With this technology, McAfee customers are better equipped to search for malicious activity in their computing environment."
About the Author:
SecurityProNews is a daily online and email publication focusing on internet security issues.
More news_security_news Articles
Insider Reports RSS Feed
|
|