发明授权
US08176477B2 Method, system and program product for optimizing emulation of a suspected malware
有权
方法,系统和程序产品,用于优化疑似恶意软件的仿真
- 专利标题: Method, system and program product for optimizing emulation of a suspected malware
- 专利标题(中): 方法,系统和程序产品,用于优化疑似恶意软件的仿真
-
申请号: US11855392申请日: 2007-09-14
-
公开(公告)号: US08176477B2公开(公告)日: 2012-05-08
- 发明人: Ji Yan Wu
- 申请人: Ji Yan Wu
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 代理商 Silvy Anna Murphy; Arthur J. Samodovitz
- 主分类号: G06F9/45
- IPC分类号: G06F9/45 ; G06F11/00
摘要:
A method, system and program product for optimizing emulation of a suspected malware. The method includes identifying, using an emulation optimizer tool, whether an instruction in a suspected malware being emulated by an emulation engine in a virtual environment signifies a long loop and, if so, generating a first hash for the loop. Further, the method includes ascertaining whether the first hash generated matches any long loop entries in a storage and, if so calculating a second hash for the long loop. Furthermore, the method includes inspecting any long loop entries ascertained to find an entry having a respective second hash matching the second hash calculated. If an entry matching the second hash calculated is found, the method further includes updating one or more states of the emulation engine, such that, execution of the long loop of the suspected malware is skipped, which optimizes emulation of the suspected malware.
公开/授权文献
信息查询