New scheme creates virtual environment where malware can be detected by its behavior
Microsoft Tuesday was awarded a patent on a new technology that may enable security applications to detect and stop malware before it enters the operating system.
In the patent, Microsoft inventor Adrian Marinescu describes a method for creating a virtualized sandbox in which the behavior of incoming executable code can be studied.
The technology would enable a software program to identify malware based on its behavior before it does any damage, rather than relying on post-infection signatures of malware that has already infected some systems. This approach may help mitigate the threats posed by the majority of new malware, which generally riffs on previously-written code.
"The virtual operating environment confines potential malware so that the systems of the host operating environment will not be adversely effected [sic] during simulation," the patent says. "As a program is being simulated, a set of behavior signatures is generated. The collected behavior signatures are suitable for analysis to determine if the program is malware."
The patent was originally filed in 2004. Microsoft has not said when or how the technology might be deployed in its product line.
— Tim Wilson, Site Editor, Dark Reading
Microsoft Corp. (Nasdaq: MSFT)
About the Author(s)
You May Also Like
Guarding the Cloud: Top 5 Cloud Security Hacks and How You Can Avoid Them
April 4, 2024Cybersecurity Strategies for Small and Med Sized Businesses
April 11, 2024Defending Against Today's Threat Landscape with MDR
April 18, 2024Securing Code in the Age of AI
April 24, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024Black Hat Asia - April 16-19 - Learn More
April 16, 2024