发明名称 Collecting malware samples via unauthorized download protection
摘要 A hook is set for one or more downloading functions. Subsequently, code is executed within an application process. Responsive to the executed code calling one of the hooked functions to download code, a return address of the called function is examined. If the return address is within a memory area not marked executable, the code is permitted to be downloaded and the downloaded code is submitted to a security server for analysis.
申请公布号 US8353033(B1) 申请公布日期 2013.01.08
申请号 US20080166785 申请日期 2008.07.02
申请人 SYMANTEC CORPORATION;CHEN JOSEPH;WOIRHAYE BRENDON 发明人 CHEN JOSEPH;WOIRHAYE BRENDON
分类号 H04L9/00 主分类号 H04L9/00
代理机构 代理人
主权项
地址
您可能感兴趣的专利