发明申请
US20070180529A1 Bypassing software services to detect malware 有权
绕过软件服务来检测恶意软件

  • 专利标题: Bypassing software services to detect malware
  • 专利标题(中): 绕过软件服务来检测恶意软件
  • 申请号: US11344360
    申请日: 2006-01-30
  • 公开(公告)号: US20070180529A1
    公开(公告)日: 2007-08-02
  • 发明人: Mihai CosteaYun Lin
  • 申请人: Mihai CosteaYun Lin
  • 申请人地址: US WA Redmond
  • 专利权人: Microsoft Corporation
  • 当前专利权人: Microsoft Corporation
  • 当前专利权人地址: US WA Redmond
  • 主分类号: G06F12/14
  • IPC分类号: G06F12/14
Bypassing software services to detect malware
摘要:
A method, apparatus, and computer readable medium are provided by aspects of the present invention to determine whether a malware is resident on a host computer. In one embodiment, a method determines whether data that is characteristic of malware is loaded in the system memory of a host computer. More specifically, the method includes causing a device communicatively connected to a host computer to issue a request to obtain data loaded in the system memory. Then, when the requested data is received, a determination is made regarding whether the data is characteristic of malware. Since, the method causes data to be obtained directly from system memory without relying on software services on the host computer, malware that employs certain stealth techniques will be identified.
公开/授权文献
信息查询
0/0