- 专利标题: KERNEL BASED EXPLOITATION DETECTION AND PREVENTION USING GRAMMATICALLY STRUCTURED RULES
-
申请号: US17161497申请日: 2021-01-28
-
公开(公告)号: US20220237286A1公开(公告)日: 2022-07-28
- 发明人: David Sánchez Lavado , Francisco Sánchez Peña
- 申请人: Malwarebytes Inc.
- 申请人地址: US CA Sata Clara
- 专利权人: Malwarebytes Inc.
- 当前专利权人: Malwarebytes Inc.
- 当前专利权人地址: US CA Sata Clara
- 主分类号: G06F21/55
- IPC分类号: G06F21/55 ; G06F21/54 ; G06F21/56
摘要:
An anti-exploitation application identifies and prevents a malicious action from occurring on a client. To do so, a monitoring system instantiated on the kernel of the operating system of the client. The monitoring system stores information describing actions taken by the processor. When the monitoring system detects a triggering action, it sends the triggering action to the anti-exploitation application to determine whether the triggering action is an exploitation action. The anti-exploitation application accesses an evidence set for the triggering action and its related actions. The anti-exploitation application generates an execution hierarchy defining the hierarchical relationships between the triggering action and its related actions and tests the hierarchy against a ruleset of grammatically structured rules. If a grammatically structured rule in the ruleset indicates that the triggering action is an exploitation action, the anti-exploitation application takes a prevention action.
信息查询