发明名称 Using asynchronous changes to memory to detect malware
摘要 A system and method for using asynchronous changes to memory to detect malware is disclosed. The technology initially receives a memory buffer location to be evaluated, the memory buffer location possibly having at least a portion of malware therein. The technology then performs a plurality of double fetches to the memory buffer location. The technology additionally compares a plurality of responses to the plurality of double fetches, wherein a plurality of similar responses to the plurality of double fetches indicates the portion of malware is not present and wherein at least two distinct responses to the plurality of double fetches indicates the portion of malware is present.
申请公布号 US2008022406(A1) 申请公布日期 2008.01.24
申请号 US20060447462 申请日期 2006.06.06
申请人 MICROSOFT CORPORATION 发明人 CLIFT NEILL M.;MORRISON JONATHAN D.
分类号 G06F12/14 主分类号 G06F12/14
代理机构 代理人
主权项
地址