SYSTEM AND METHOD FOR DETECTING MULTI-COMPONENT MALWARE

Patent №

US 7,620,992

Granted

2009-11-17

Filed 2007

Owner

KASPERSKY LAB, ZAO

Lab

AI components

3

kr · planning · hardware

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

11866287

Malicious behavior of a computer program is detected using an emulation engine, an event detector and an event analyzer. The emulation engine includes a system emulator configured to emulate, in an isolated computer environment, at least a part of a computer system and a program emulator configured to emulate in the isolated computer environment execution of the computer program, including execution of a plurality of executable components of the computer program, such as execution processes and threads. The event detector is configured to monitor events being generated by two or more of the executable components. The event analyzer is configured to determine, substantially in real time, based at least on one or more events generated by each of two or more of the plurality of executable components whether or not the computer program exhibits malicious behavior, wherein individually one or more of the plurality of executable components may exhibit benign behavior.

AI classification

AI hardware1.00
Knowledge representation0.85
Planning0.65
Natural language0.00
Vision0.00
Machine learning0.00
Evolutionary computation0.00
Speech0.00

Ownership

KASPERSKY LAB, ZAO

assignment · 203220887

Assignors

MONASTRYSKY, ALEXEY V., SOBKO, ANDREY V., PAVLYUSHCHIK, MIKHAIL A.

On an employer assignment, the assignors are typically the inventors.

© 2026 NYSGPT2525 LLC