Invention Grant
US08353033B1 Collecting malware samples via unauthorized download protection 有权
通过未经授权的下载保护收集恶意软件样本

Collecting malware samples via unauthorized download protection
Abstract:
A hook is set for one or more downloading functions. Subsequently, code is executed within an application process. Responsive to the executed code calling one of the hooked functions to download code, a return address of the called function is examined. If the return address is within a memory area not marked executable, the code is permitted to be downloaded and the downloaded code is submitted to a security server for analysis.
Information query
Patent Agency Ranking
0/0