170 The State of the Art in Intrusion Prevention and Detection
One of the successful mechanisms to resolve the aforementioned problem is the use of articial
runtime environment emulation. However, it is not a lightweight detection mechanism, but it has
high success rates in detecting unknown attacks. Environment emulation utilizes the idea of virtual
machines; the malware detection tool provides a virtual machine with an independent and isolated
operating system and allows malware to perform its routines freely within the virtual environment.
The execution behavior of the suspicious application is being continuously examined while the
malware is not aware. Most of the stealth and anti-heuristic techniques are irrelevant in this case
as t