Invention Grant
- Patent Title: Detection of spyware threats within virtual machine
- Patent Title (中): 检测虚拟机中的间谍软件威胁
-
Application No.: US11426370Application Date: 2006-06-26
-
Publication No.: US08196205B2Publication Date: 2012-06-05
- Inventor: Steven Gribble , Henry Levy , Alexander Moshchuk , Tanya Bragin
- Applicant: Steven Gribble , Henry Levy , Alexander Moshchuk , Tanya Bragin
- Applicant Address: US WA Seattle
- Assignee: University of Washington through its Center for Commercialization
- Current Assignee: University of Washington through its Center for Commercialization
- Current Assignee Address: US WA Seattle
- Agency: University of Washington Center for Commercialization
- Main IPC: G06F11/00
- IPC: G06F11/00 ; H04L9/32

Abstract:
A system analyzes content accessed at a network site to determine whether it is malicious. The system employs a tool able to identify spyware that is piggy-backed on executable files (such as software downloads) and is able to detect “drive-by download” attacks that install software on the victim's computer when a page is rendered by a browser program. The tool uses a virtual machine (VM) to sandbox and analyze potentially malicious content. By installing and running executable files within a clean VM environment, commercial anti-spyware tools can be employed to determine whether a specific executable contains piggy-backed spyware. By visiting a Web page with an unmodified browser inside a clean VM environment, predefined “triggers,” such as the installation of a new library, or the creation of a new process, can be used to determine whether the page mounts a drive-by download attack.
Public/Granted literature
- US20070174915A1 DETECTION OF SPYWARE THREATS WITHIN VIRTUAL MACHINE Public/Granted day:2007-07-26
Information query