发明名称 Bypassing software services to detect malware
摘要 A method, apparatus, and computer readable medium are provided by aspects of the present invention to determine whether a malware is resident on a host computer. In one embodiment, a method determines whether data that is characteristic of malware is loaded in the system memory of a host computer. More specifically, the method includes causing a device communicatively connected to a host computer to issue a request to obtain data loaded in the system memory. Then, when the requested data is received, a determination is made regarding whether the data is characteristic of malware. Since, the method causes data to be obtained directly from system memory without relying on software services on the host computer, malware that employs certain stealth techniques will be identified.
申请公布号 US2007180529(A1) 申请公布日期 2007.08.02
申请号 US20060344360 申请日期 2006.01.30
申请人 MICROSOFT CORPORATION 发明人 COSTEA MIHAI;LIN YUN
分类号 G06F12/14 主分类号 G06F12/14
代理机构 代理人
主权项
地址