- 专利标题: System and method for analyzing a log in a virtual machine based on a template
-
申请号: US16715599申请日: 2019-12-16
-
公开(公告)号: US11048795B2公开(公告)日: 2021-06-29
- 发明人: Vladislav V. Pintiysky , Denis V. Anikin , Denis Y. Kobychev , Maxim Y. Golovkin , Vitaly V. Butuzov , Dmitry V. Karasovsky , Dmitry A. Kirsanov
- 申请人: AO Kaspersky Lab
- 申请人地址: RU Moscow
- 专利权人: AO Kaspersky Lab
- 当前专利权人: AO Kaspersky Lab
- 当前专利权人地址: RU Moscow
- 代理机构: Arent Fox LLP
- 代理商 Michael Fainberg
- 主分类号: G06F21/00
- IPC分类号: G06F21/00 ; G06F21/53 ; G06F21/56 ; G06F21/55 ; G06F21/60
摘要:
Disclosed is a method for analyzing a log for conducting an antivirus scan of a file. The method includes opening a file in a virtual machine. The opening of the file includes execution of a guest process having a thread in a virtual processor of the virtual machine. A plurality of events in the thread of the guest process is intercepted. Registers associated with a system call made during execution of the first thread of the guest process are determined. Execution of the thread of the guest process is halted. In a log associated with the opening of the file, information is saved indicating events intercepted during execution of the thread in an altered guest physical memory page, and context data of the virtual processor. Using at least one template having rules, the saved log is analyzed to determine whether the file opened in the virtual machine is harmful.
信息查询