Invention Grant
- Patent Title: System and method for process hollowing detection
-
Application No.: US15457734Application Date: 2017-03-13
-
Publication No.: US10043000B2Publication Date: 2018-08-07
- Inventor: Jeffrey Albin Kraemer , Paul Matthew Drapeau
- Applicant: Carbon Black, Inc.
- Applicant Address: US MA Waltham
- Assignee: Carbon Black, Inc.
- Current Assignee: Carbon Black, Inc.
- Current Assignee Address: US MA Waltham
- Agency: HoustonHogle LLP
- Main IPC: G06F21/52
- IPC: G06F21/52 ; H04L29/06

Abstract:
A method and system for remediating a process hollowing intrusion on a user device comprising detecting a process starting on the user device, preparing the process to monitor Application Programming Interface (API) calls between the process and an operating system of the user device, determining whether the process is associated with a process hollowing intrusion based on information associated with the process and/or the API calls, and executing security policies against the process associated with the process hollowing intrusion. In examples, it is determined whether the child process is associated with a process hollowing intrusion in response to determining whether one or more API calls associated with known process hollowing intrusions modify executable memory of and/or modify an entry point address of the child process.
Public/Granted literature
- US20170272462A1 System and Method for Process Hollowing Detection Public/Granted day:2017-09-21
Information query