The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 13, 2017

Filed:

May. 31, 2016
Applicant:

AO Kaspersky Lab, Moscow, RU;

Inventors:

Alexey V. Monastyrsky, Moscow, RU;

Vitaly V. Butuzov, Moscow, RU;

Maxim Y. Golovkin, Moscow, RU;

Dmitry V. Karasovsky, Moscow, RU;

Vladislav V. Pintiysky, Moscow, RU;

Denis Y. Kobychev, Moscow, RU;

Assignee:

AO Kaspersky Lab, Moscow, RU;

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/56 (2013.01); G06F 17/30 (2006.01); G06F 9/455 (2006.01);
U.S. Cl.
CPC ...
G06F 21/566 (2013.01); G06F 9/45533 (2013.01); G06F 17/30477 (2013.01); G06F 2221/033 (2013.01);
Abstract

A method and system are provided for performing an antivirus scan of a file on a virtual machine. An example method includes performing a first execution of the file on the virtual machine, recording a first log that includes an API function call and an internal event detected during execution, and determining if any signatures in the log are stored in a signatures database. Moreover, if no signatures in the first log are found in the first database of signatures, the file is classified as not malicious. In contrast, if at least one signature is found, a second execution of the file is perform and a second log is recorded that includes a detected internal event. Moreover, the method includes determining if any signatures in the second log are stored in a second database of signatures; and classifying the file as not malicious if no signatures are found.


Find Patent Forward Citations

Loading…