Mandiant, Inc.
Detecting delayed activation malware using a run-time monitoring agent and time-dilation logic

Last updated:

Abstract:

A malicious content detection (MCD) system and a computerized method for manipulating time uses a time controller operating within the MCD system in order to capture the behavior of delayed activation malware (time bombs). The time controller may include a monitoring agent located in a software layer of a virtual environment configured to intercept software calls (e.g., API calls or system calls) and/or other time checks that seek to obtain a "current time," and time-dilation action logic located in a different layer configured to respond to the software calls by providing a "false" current time that indicates considerably more time has transpired than the real clock.

Status:
Grant
Type:

Utility

Filling date:

29 Jun 2016

Issue date:

27 Oct 2020