Invention Grant
- Patent Title: Method of and system for malicious software detection using critical address space protection
- Patent Title (中): 使用关键地址空间保护的恶意软件检测方法和系统
-
Application No.: US12322220Application Date: 2009-01-29
-
Publication No.: US08515075B1Publication Date: 2013-08-20
- Inventor: Suman Saraf , Sharad Agrawal , Pankaj Kumar
- Applicant: Suman Saraf , Sharad Agrawal , Pankaj Kumar
- Applicant Address: US CA Santa Clara
- Assignee: McAfee, Inc.
- Current Assignee: McAfee, Inc.
- Current Assignee Address: US CA Santa Clara
- Agency: Patent Capital Group
- Main IPC: G06F21/00
- IPC: G06F21/00

Abstract:
A method of identifying malicious code based on identifying software executing out of writable memory of the computer system. In one embodiment, the identification of the malicious code occurs when the code accesses a predetermined memory address. This address can reside in the address space of an application, a library, or an operating system component. In one embodiment, the access to the predetermined address generates an exception invoking exception handling code. The exception handling code checks the memory attributes of the code that caused the exception and determines whether the code was running in writeable memory.
Information query