发明名称 DETECTION OF MALWARE
摘要 Particular embodiments described herein provide for an electronic device that can be configured to monitor a process, determine if the process is parsing to look for one or more system functions, and flag the process if the process is parsing to look for one or more system system functions. In an example, the process can be determined to be parsing to look for one or more system functions if the process parses portable executable headers to find and interpret dynamic link library tables. In another example, the process can be determined to be parsing to look for one or more system functions if the process calls GetProcAddress.
申请公布号 WO2017003587(A1) 申请公布日期 2017.01.05
申请号 WO2016US33977 申请日期 2016.05.25
申请人 MCAFEE, INC. 发明人 EDWARDS, Jonathan L.;SPURLOCK, Joel R.
分类号 G06F21/56;G06F21/57;H04L29/06 主分类号 G06F21/56
代理机构 代理人
主权项
地址