System and methods for detecting harmful files of different formats in virtual environments
US9348998B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Mar 9, 2015 |
| Grant date | May 24, 2016 |
| Priority date | — |
| Expiry date | Mar 9, 2035 |
Classification
- Technology area (CPC G)Physics
- CPC primaryG06F2221/033
- WIPO fieldComputer technology
- WIPO sectorElectrical engineering
Abstract
Disclosed are systems, methods and computer program products for detection of harmful files of different formats. An example method includes: receiving a suspicious file; determining a file format of the suspicious file; determining, using antivirus software, if the suspicious file is clean or harmful; and when the antivirus software fails to determine whether the suspicious file is clean or harmful, selecting, based on at least the file format of the suspicious file, a configuration of a virtual machine for analyzing a maliciousness of the suspicious file by at least: selecting a program associated with the file format of the suspicious file, opening the suspicious file using the associated program in the virtual machine, collecting data of at least one activity on the virtual machine, and analyzing the data to determine the maliciousness of the suspicious file.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.