Invention Grant
US08515075B1 Method of and system for malicious software detection using critical address space protection 有权
使用关键地址空间保护的恶意软件检测方法和系统

Method of and system for malicious software detection using critical address space protection
Abstract:
A method of identifying malicious code based on identifying software executing out of writable memory of the computer system. In one embodiment, the identification of the malicious code occurs when the code accesses a predetermined memory address. This address can reside in the address space of an application, a library, or an operating system component. In one embodiment, the access to the predetermined address generates an exception invoking exception handling code. The exception handling code checks the memory attributes of the code that caused the exception and determines whether the code was running in writeable memory.
Information query
Patent Agency Ranking
0/0