IP Library › Granted Patent US 10,452,817
Granted Patent B1
US 10,452,817 · App. 12/420,525 · Granted Oct 22, 2019

File input/output redirection in an API-proxy-based application emulator

Inventors: Sun Mingyan (Nanjing, CN); Lo Chien Ping (Yonghe, TW); Fan Chi-Huang (Sanchong, TW)
Assignee: TREND MICRO INC
G06F21/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,452,817
App. No.
12/420,525
Filed
Apr 8, 2009
Granted
Oct 22, 2019
Kind
B1
Art Unit
3621
USPC
726/30
Abstract

Applications running in an API-proxy-based emulator are prevented from infecting a PC's hard disk when executing file I/O commands. Such commands are redirected to an I/O redirection engine instead of going directly to the PC's normal operating system where it can potentially harm files in on the hard disk. The redirection engine executes the file I/O command using a private storage area in the hard disk that is not accessible by the PC's normal operating system. If a file that is the subject of a file I/O command from an emulated application is not in the private storage area, a copy is made from the original that is presumed to exist in the public storage area. This copy is then acted on by the command and is stored in the private storage area, which can be described as a controlled, quarantined storage space on the hard disk. In this manner the PC's (or any computing device's) hard disk is defended from potential malware that may originate from applications running in emulated environments.

Claims (21)

1. A method of defending a computing device against malware, the method comprising:

executing an application, the application issuing a file input/output (“I/O”) command operating on a file located in persistent storage of said computing device, wherein said persistent storage is a hard disk of said computing device;

transmitting the file I/O command to an operating system of said computing device;

transmitting the file I/O command from the operating system to a redirection module;

analyzing the file I/O command in the redirection module, wherein said file that the file I/O command operates on is not analyzed;

determining whether the application is executing in an emulator program which is executing on said computing device or in an actual operating system of said computing device by checking a process associated with the file I/O command;

determining that the file I/O command is from said application running in said emulator program,

determining that said file has not been previously modified by any application running in said emulator program and that said file I/O command requires modifying said file in said persistent storage of said computing device,

copying said file from a public storage area of said persistent storage to a private storage area of said persistent storage, and

executing the file I/O command and changing said file in said private storage area of said persistent storage, wherein said application running in said emulator program does not execute the file I/O command in said public storage area.

2. A method as recited in claim 1 further comprising:

determining whether the application is executing in said emulator program by examining a process identifier, a process name, a process path or a process hash value of the application.

3. A method as recited in claim 1 further comprising:

examining a file update log.

4. A method as recited in claim 1 wherein the redirection module maintains a log of file updates.

5. A method as recited in claim 1 further comprising:

registering the redirection module with the operating system.

6. A method as recited in claim 1 wherein said analyzing is performed by a command analysis module in the redirection module.

7. A method as recited in claim 1 further comprising:

determining whether the file I/O command is a write command, a modify command, or a delete command.

8. A method as recited in claim 1 wherein said private storage area is not accessible by said operating system of said computing device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2019
From: SUN, MINGYAN; PING, LO CHIEN; FAN, CHI-HUANG
To: TREND MICRO INC,
Reel/Frame 050146/0978 →
Cited By (3)
US 12,321,456 US 12,323,464 US 12,333,008