IP Library Granted Patent US 8,782,791
Granted Patent B2
US 8,782,791 · App. 12/958,306 · Granted Jul 15, 2014

Computer virus detection systems and methods

Inventor: Anand D. Sankruthi (Chennai, IN)
Assignee: Symantec Corporation
H04L63/145H04L63/1416H04L63/1491H04L63/1425G06F21/564
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,782,791
App. No.
12/958,306
Granted
Jul 15, 2014
Kind
B2
Abstract

Systems and methods for computer virus detection are presented. In one embodiment; an computer virus detection method includes: receiving an indication of a change to a file; performing a virus analysis process, including executing the changes to the file in a virtual machine and examining results of the executing the changes; and handling the file based upon the virus analysis. The virus analysis can be performed in a system in which the change to the file occurs. Handling the file can include treating the file as potentially infected with a virus based upon the virus analysis. In one exemplary implementation, examining the results includes comparing the results of executing the changes to the file to other results from executing changes to another file, wherein the file is identified as potentially infected with a virus if the examining results indicates the results of executing the changes to the file are similar to results from executing changes to another file. Examining results includes examining behavior resulting from executing the file (e.g., examining system calls, etc.). Outcome of the examining results can be forwarded for utilization in developing virus data sets.

Claims (33)

1. A computer virus detection method comprising:

performing a virus analysis process, including:

executing changes to a first and a second file in a virtual machine;

comparing resulting behavior of executing said changes to said first file in said virtual machine to resulting behavior of executing said changes to said second file in said virtual machine; and

executing said changes to said first and second files outside the virtual machine based upon receiving an indication from said virus analysis process that said first and second files are not infected;

wherein said first and second files are identified as potentially infected with a virus if said resulting behavior of executing said changes to said first file in said virtual machine shares common characteristics with said resulting behavior of executing said changes to said second file in said virtual machine.

2. The computer virus detection method of claim 1 wherein said performing said virus analysis process is performed in a system in which said changes to said first and second files occur.

3. The computer virus detection method of claim 1 wherein said first and second files are treated as potentially infected with a virus based upon said virus analysis process indicating behavior of both the first and second files share common characteristics.

4. The computer virus detection method of claim 1 wherein said first and second files are treated as potentially infected with a virus based upon said virus analysis indicating behavior of said first and second changed files and a process that directed said change share common characteristics.

5. The computer virus detection method of claim 1 wherein said examining said behavior includes examining system calls.

6. The computer virus detection method of claim 1 further comprising forwarding an outcome of said examining results for utilization in developing virus data sets.

7. A non-transitory computer readable storage medium having stored thereon computer executable instructions that, when executed by a computer system, cause the computer system to perform a method comprising:

performing a virus analysis process, including:

executing changes to a first and a second file in a virtual machine;

comparing resulting behavior of executing said changes to said first file in said virtual machine to resulting behavior of executing said changes to said second file in said virtual machine; and

executing said changes to said first and second files outside the virtual machine based upon receiving an indication from said virus analysis process that said file is first and second files are not infected;

wherein said first and second files are identified as potentially infected with a virus if said resulting behavior of executing said changes to said first file in said virtual machine shares common characteristics with said resulting behavior of executing said changes to said second file in said virtual machine.

8. The non-transitory tangible computer readable storage medium of claim 7 wherein said performing said virus analysis process is performed in a system in which said changes to said first and second files occur.

9. The non-transitory tangible computer readable storage medium of claim 7 wherein said first and second files are treated as potentially infected with a virus based upon said virus analysis process indicating behavior of both the first and second files share common characteristics.

10. The non-transitory tangible computer readable storage medium of claim 7 wherein said first and second files are treated as potentially infected with a virus based upon said virus analysis indicating behavior of said first and second changed files and a process that directed said change share common characteristics.

11. The non-transitory tangible computer readable storage medium of claim 7 wherein said examining said behavior includes examining system calls.

12. The non-transitory tangible computer readable storage medium of claim 7 further comprising forwarding an outcome of said examining results for utilization in developing virus data sets.

13. A computer system, comprising:

a computer system having a processor coupled to a non-transitory computer readable storage medium and executing computer readable code which causes the computer system to perform operations including:

performing a virus analysis process, including:

executing changes to a first and a second file in a virtual machine;

comparing resulting behavior of executing said changes to said first file in said virtual machine to resulting behavior of executing said changes to said second file in said virtual machine; and

executing said changes to said first and second files outside the virtual machine based upon receiving an indication from said virus analysis process that said file is first and second files are not infected;

wherein said first and second files are identified as potentially infected with a virus if said resulting behavior of executing said changes to said first file in said virtual machine shares common characteristics with said resulting behavior of executing said changes to said second file in said virtual machine.

14. The computer system of claim 13 wherein said performing said virus analysis process is performed in a system in which said changes to said first and second files occur.

15. The computer system of claim 13 wherein said first and second files are treated as potentially infected with a virus based upon said virus analysis process indicating behavior of both the first and second files share common characteristics.

16. The computer system of claim 13 wherein said first and second files are treated as potentially infected with a virus based upon said virus analysis indicating behavior of said first and second changed files and a process that directed said change share common characteristics.

17. The computer system method of claim 13 further comprising forwarding an outcome of said examining results for utilization in developing virus data sets.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2010
From: SANKRUTHI, ANAND D.
To: SYMANTEC CORPORATION
Reel/Frame 025435/0834 →
Continuity (1)
Related Publication 20120144488A1 · Jun 7, 2012