发明名称 System and method for detecting malicious code in random access memory
摘要 Disclosed are system and method for detecting malicious code in random access memory. An exemplary method comprises: detecting, by a hardware processor, a process of an untrusted program on the computer; identifying, by the hardware processor, function calls made by the process of the untrusted program, including inter-process function calls made by the process to a destination process; determining, by the hardware processor, whether to perform malware analysis of a code in an address space of the destination process that was subject of an inter-process function call made by the process of the untrusted program; and when it is determined to perform malware analysis, analyzing the code in an address space of the destination process that was subject of an inter-process function call made by the process of the untrusted program using antivirus software executable by the hardware processor.
申请公布号 US9407648(B1) 申请公布日期 2016.08.02
申请号 US201514951915 申请日期 2015.11.25
申请人 AO Kaspersky Lab 发明人 Pavlyushchik Mikhail A.;Monastyrsky Alexey V.;Nazarov Denis A.
分类号 H04L29/06 主分类号 H04L29/06
代理机构 Arent Fox LLP 代理人 Arent Fox LLP ;Fainberg Michael
主权项 1. A method for detection of malware on a computer, the method comprising: detecting, by a hardware processor, a process of an untrusted program on the computer; identifying, by the hardware processor, function calls made by the process of the untrusted program, including inter-process function calls made by the process to a destination process; collecting, by the hardware processor, information about the untrusted program; applying, by the hardware processor, heuristic rules to information about the identified function calls and the information about the untrusted program to determine whether to perform malware analysis of a code in an address space of the destination process that was subject of an inter-process function call made by the process of the untrusted program; and when it is determined to perform malware analysis, analyzing the code in an address space of the destination process that was subject of the inter-process function call made by the process of the untrusted program using antivirus software executable by the hardware processor.
地址 Moscow RU