- 专利标题: System and method for detecting interpreter-based exploit attacks
-
申请号: US16042998申请日: 2018-07-23
-
公开(公告)号: US10887328B1公开(公告)日: 2021-01-05
- 发明人: Sushant Paithane , Sai Omkar Vashisht
- 申请人: FireEye, Inc.
- 申请人地址: US CA Milpitas
- 专利权人: FireEye, Inc.
- 当前专利权人: FireEye, Inc.
- 当前专利权人地址: US CA Milpitas
- 代理机构: Rutan & Tucker, LLP
- 主分类号: G06F21/56
- IPC分类号: G06F21/56 ; H04L29/06 ; G06F21/55 ; G06F21/53
摘要:
For one embodiment, a computerized method for detecting exploit attacks on an interpreter comprises configuring a virtual machine including a user mode and a kernel mode and processing an object by an application operating in the user mode of the virtual machine. Responsive to the processing of the object, detecting a loading of an interpreter. Furthermore, responsive to the loading of the interpreter, inserting one or more intercept points for detecting one or more types of software calls from the interpreter or for detecting a certain type or certain types of activities occurring within the interpreter. Thereafter, an exploit attack is detected as being conducted by the object in response to the interpreter invoking a software call that corresponds to the one or more types of software calls that is considered anomalous when invoked by the interpreter or an anomalous activity being conducted within the interpreter.
信息查询