The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 29, 2021

Filed:

Dec. 16, 2019
Applicant:

AO Kaspersky Lab, Moscow, RU;

Inventors:

Vladislav V. Pintiysky, Moscow, RU;

Denis V. Anikin, Moscow, RU;

Denis Y. Kobychev, Moscow, RU;

Maxim Y. Golovkin, Moscow, RU;

Vitaly V. Butuzov, Moscow, RU;

Dmitry V. Karasovsky, Moscow, RU;

Dmitry A. Kirsanov, Moscow, RU;

Assignee:

AO Kaspersky Lab, Moscow, RU;

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/00 (2013.01); G06F 21/53 (2013.01); G06F 21/56 (2013.01); G06F 21/55 (2013.01); G06F 21/60 (2013.01);
U.S. Cl.
CPC ...
G06F 21/53 (2013.01); G06F 21/552 (2013.01); G06F 21/566 (2013.01); G06F 21/568 (2013.01); G06F 21/60 (2013.01);
Abstract

Disclosed is a method for analyzing a log for conducting an antivirus scan of a file. The method includes opening a file in a virtual machine. The opening of the file includes execution of a guest process having a thread in a virtual processor of the virtual machine. A plurality of events in the thread of the guest process is intercepted. Registers associated with a system call made during execution of the first thread of the guest process are determined. Execution of the thread of the guest process is halted. In a log associated with the opening of the file, information is saved indicating events intercepted during execution of the thread in an altered guest physical memory page, and context data of the virtual processor. Using at least one template having rules, the saved log is analyzed to determine whether the file opened in the virtual machine is harmful.


Find Patent Forward Citations

Loading…