New Microsoft virus-scanning patent

By Niels on .

*sigh*, now I'm really getting exhausted on what's coming out of Redmond.

Ars Technica writes on a new patent Microsoft got after two years of waiting on it.

The patent describes as:

"...A system, method, and computer readable medium for the proactive detection of malware in operating systems that receive application programming interface (API) calls is provided. A virtual operating environment for simulating the execution of programs and determining if the programs are malware is created. The virtual operating environment confines potential malware so that the systems of the host operating environment will not be adversely effected. During simulation, a behavior signature is generated based on the API calls issued by potential malware. The behavior signature is suitable for analysis to determine whether the simulated executable is malware...."

So what do I actually read here? Yes, they describe a summary to "detect" certain API calls and block identified "suspicous" API-calls! Well, that certainly doesn't sound very modern nor such a good solution. Why couldn't they come up with a good security model that would deny malicous API calls upfront?