DETECTION OF SPYWARE THREATS WITHIN VIRTUAL MACHINE

Patent №

US 8,196,205

Granted

2012-06-05

Filed 2006

Owner

UNIVERSITY OF WASHINGTON

Lab

AI components

2

kr · planning

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

11426370

A system analyzes content accessed at a network site to determine whether it is malicious. The system employs a tool able to identify spyware that is piggy-backed on executable files (such as software downloads) and is able to detect “drive-by download” attacks that install software on the victim's computer when a page is rendered by a browser program. The tool uses a virtual machine (VM) to sandbox and analyze potentially malicious content. By installing and running executable files within a clean VM environment, commercial anti-spyware tools can be employed to determine whether a specific executable contains piggy-backed spyware. By visiting a Web page with an unmodified browser inside a clean VM environment, predefined “triggers,” such as the installation of a new library, or the creation of a new process, can be used to determine whether the page mounts a drive-by download attack.

Knowledge representationPlanningH04L 63/1483G06F 9/45558G06F 21/53G06F 21/566H04L 63/1416G06F 21/554G06F 2009/45587H04L 63/14+1 more

AI classification

Knowledge representation0.95
Planning0.95
Evolutionary computation0.05
AI hardware0.03
Natural language0.00
Vision0.00
Machine learning0.00
Speech0.00

Ownership

UNIVERSITY OF WASHINGTON

assignment · 178540534

From the same owner

© 2026 NYSGPT2525 LLC