IP Library Granted Patent US 7,739,100
Granted Patent B1
US 7,739,100 · App. 11/253,094 · Granted Jun 15, 2010

Emulation system, method and computer program product for malware detection by back-stepping in program code

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,739,100
App. No.
11/253,094
Granted
Jun 15, 2010
Kind
B1
Abstract

A system, method, and computer program product are provided for detecting malware. In use, a search is conducted for known elements of computer code. Upon the detection of at least one known element of computer code, various operations are performed. In particular, the present technique steps back in the computer code, and emulates the computer code. Such emulation and stepping are performed for detecting malware.

Claims (40)

1. A method, comprising:

searching for known elements of computer code among a plurality of computer code elements including a first computer code element and a second computer code element subsequent to the first computer code element, the computer code elements including parts of the computer code and the known elements of the computer code including elements of the computer code that are both known before emulation and are capable of being located in the computer code;

upon detection of the second computer code element including at least one known element of computer code,

stepping back in the computer code by moving from the second computer code element to the first computer code element, and

emulating the computer code as a function of the stepping back; detecting malware based on the emulation and the stepping;

comparing results of the emulation with data in a database;

wherein the results include parameters associated with execution of the computer code.

2. The method of claim 1 , wherein the at least one known element of the computer code is identified as a key point in the computer code.

3. The method of claim 2 , wherein the key point is associated with an application programming interface.

4. The method of claim 2 , wherein the key point is associated with an operating system application programming interface.

5. The method of claim 2 , wherein the stepping back occurs from the key point.

6. The method of claim 1 , wherein the database includes a malware database.

7. The method of claim 2 , wherein the parameters include parameters with which the execution of the computer code arrives at the key point.

8. The method of claim 2 , and further comprising repeating the stepping and the emulation in association with a plurality of the key points to generate a set of results.

9. The method of claim 8 , and further comprising comparing the set of results of the emulation with the data in the database.

10. The method of claim 1 , wherein the stepping is performed prior to the emulation.

11. The method of claim 1 , wherein the malware includes viruses.

12. The method of claim 1 , wherein the malware is selected from the group consisting of malware, spyware, and unwanted programs.

13. The method of claim 1 , wherein the stepping is minimized by the stepping back from a key point.

14. The method of claim 2 , wherein the emulation is carried out on a portion of the computer code starting with a point defined by the stepping and the key point.

15. The method of claim 1 , wherein the stepping reduces an amount of the computer code to be emulated.

16. The method of claim 2 , and further comprising determining whether an additional key point exists, and repeating the stepping and the emulation in association with the additional key point.

17. A computer code embodied on a computer readable medium, comprising:

a computer segment for searching for known elements of computer code among a plurality of computer code elements including a first computer code element and a second computer code element subsequent to the first computer code element, the computer code elements including parts of the computer code and the known elements of the computer code including elements of the computer code that are both known before emulation and are capable of being located in the computer code;

a computer segment for, upon the detection of the second computer code element including at least one known element of computer code,

stepping back in the computer code by moving from the second computer code element to the first computer code element, and

emulating the computer code as a function of the stepping back;

a computer segment for detecting malware based on the emulation and the stepping;

a computer segment for comparing results of the emulation with data in a database;

wherein the results include parameters associated with execution of the computer code.

18. A system, comprising:

a processor coupled to memory,

the processor adapted for searching for known elements of computer code among a plurality of computer code elements including a first computer code element and a second computer code element subsequent to the first computer code element, the computer code elements including parts of the computer code and the known elements of the computer code including elements of the computer code that are both known before emulation and are capable of being located in the computer code;

the processor adapted for stepping back in the computer code by moving from the second computer code element to the first computer code element, and emulating the computer code as a function of the stepping back, upon the detection of the second computer code element including at least one known element of computer code;

the processor adapted for detecting malware based on the emulation and the stepping; and

the processor adapted for comparing results of the emulation with data in a database;

wherein the results include parameters associated with execution of the computer code.

19. The method of claim 1 , wherein the known elements of computer code include one or more of application programming interface (API) calls, dynamic link libraries (DLLs), static link libraries, and computer instructions.

20. The method of claim 1 , wherein the stepping back involves moving to a previous computer code element.

21. The method of claim 7 , wherein the parameters with which the execution of the computer code arrives at the key point include parameters on a stack and pointers to memory and associated contents.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2005
From: MUTTIK, IGOR G.; TEBLYASHKIN, IVAN
To: MCAFEE, INC.
Reel/Frame 017118/0333 →