Application behavior based malware detection

Number of patents in Portfolio can not be more than 2000

United States of America Patent

PATENT NO 7779472
SERIAL NO

11247349

Stats

ATTORNEY / AGENT: (SPONSORED)

Importance

Loading Importance Indicators... loading....

Abstract

See full text

An executable file is loaded into a virtual machine arranged to emulate the instructions of said executable file. The virtual machine keeps track of application programming interfaces (APIs) used by the executable file during emulation. The executable file is scanned to determine names of (APIs) used. Behavior flags are set if certain conditions occur within the executable file. The APIs determined during emulation and during scanning are compared with a set of known behaviors. A match of the APIs and the known behaviors indicates a high risk of malware. A determination of malware being present is based upon any matches and any behavior flags that are set.

Loading the Abstract Image... loading....

First Claim

See full text

Family

Loading Family data... loading....

Patent Owner(s)

Patent OwnerAddress
TREND MICRO INCSHINJUKU MAYNDS TOWER 30F 2-1-1 YOYOGI SHIBUYA-KU TOKYO 151-0053

International Classification(s)

  • [Classification Symbol]
  • [Patents Count]

Inventor(s)

Inventor Name Address # of filed Patents Total Citations
Lou, Vic Chung Ho, TW 2 131

Cited Art Landscape

Load Citation

Patent Citation Ranking

Forward Cite Landscape

Load Citation