Invention Grant
- Patent Title: Evaluating shellcode findings
- Patent Title (中): 评估shellcode结果
-
Application No.: US12819234Application Date: 2010-06-21
-
Publication No.: US08413246B2Publication Date: 2013-04-02
- Inventor: Jinwook Shin , John Joseph Lambert , Joshua Lackey
- Applicant: Jinwook Shin , John Joseph Lambert , Joshua Lackey
- Applicant Address: US WA Redmond
- Assignee: Microsoft Corporation
- Current Assignee: Microsoft Corporation
- Current Assignee Address: US WA Redmond
- Agency: Hope Baldauff Hartman, LLC
- Main IPC: G06F21/00
- IPC: G06F21/00

Abstract:
Concepts and technologies are described herein for evaluating shellcode findings. In accordance with the concepts and technologies disclosed herein, shellcode findings can be evaluated to determine if the shellcode findings are legitimate, or if the shellcode findings are false positive shellcode findings. Legitimate shellcode findings can be determined based not simply upon patterns associated with the suspected shellcode itself, but also based upon a pattern of bit-level entropy in the memory around the suspected shellcode. Mathematical models of the memory can be generated and analyzed to determine if the shellcode finding is legitimate.
Public/Granted literature
- US20110314544A1 EVALUATING SHELL CODE FINDINGS Public/Granted day:2011-12-22
Information query