发明名称 IMPROVED MALWARE DETECTION
摘要 <p>A method of detecting suspicious code that has been injected into a process. The method comprises: identifying suspicious executable memory areas assigned to the process and, for each thread in the process, inspecting a stack associated with the thread to identify a potential return address; determining whether or not the potential return address is located within a suspicious memory area; and, if the potential return address is located within a suspicious memory area, determining whether or not the instruction at the address preceding the potential return address is a function call and, if yes, determining that the potential return address is a true return address and identifying the thread and associated code as suspicious.</p>
申请公布号 WO2014124806(A1) 申请公布日期 2014.08.21
申请号 WO2014EP51650 申请日期 2014.01.28
申请人 F-SECURE CORPORATION 发明人 SUOMINEN, MIKKO
分类号 G06F21/52 主分类号 G06F21/52
代理机构 代理人
主权项
地址