SYSTEM AND METHOD FOR COUNTERING DETECTION OF EMULATION BY MALWARE

Patent №

US 8,910,286

Granted

2014-12-09

Filed 2013

Owner

KASPERSKY LAB ZAO

Lab

AI components

1

hardware

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

14036753

Instructions of an application program are emulated such that they are carried out sequentially in a first virtual execution environment that represents the user-mode data processing of the operating system. A system API call requesting execution of a user-mode system function is detected. In response, the instructions of the user-mode system function called by the API are emulated according to a second emulation mode in which the instructions of the user-mode system function are carried out sequentially in a second virtual execution environment that represents the user-mode data processing of the operating system, including tracking certain processor and memory states affected by the instructions of the user-mode system function. Results of the emulating of the application program instructions according to the first emulation mode are analyzed for any presence of malicious code.

AI classification

AI hardware1.00
Planning0.01
Natural language0.00
Vision0.00
Evolutionary computation0.00
Knowledge representation0.00
Speech0.00
Machine learning0.00

Ownership

KASPERSKY LAB ZAO

assignment · 313170278

Assignors

BELOV, SERGEY

On an employer assignment, the assignors are typically the inventors.

© 2026 NYSGPT2525 LLC