Mandiant, Inc.
Detecting delayed activation malware using a run-time monitoring agent and time-dilation logic
Last updated:
Abstract:
A malicious content detection (MCD) system and a computerized method for manipulating time uses a time controller operating within the MCD system in order to capture the behavior of delayed activation malware (time bombs). The time controller may include a monitoring agent located in a software layer of a virtual environment configured to intercept software calls (e.g., API calls or system calls) and/or other time checks that seek to obtain a "current time," and time-dilation action logic located in a different layer configured to respond to the software calls by providing a "false" current time that indicates considerably more time has transpired than the real clock.
Status:
Grant
Type:
Utility
Filling date:
29 Jun 2016
Issue date:
27 Oct 2020