Invention Grant
- Patent Title: Method to detect application execution hijacking using memory protection
-
Application No.: US14871987Application Date: 2015-09-30
-
Publication No.: US10210329B1Publication Date: 2019-02-19
- Inventor: Amit Malik , Reghav Pande , Aakash Jain
- Applicant: FIREEYE, INC.
- Applicant Address: US CA Milpitas
- Assignee: FireEye, Inc.
- Current Assignee: FireEye, Inc.
- Current Assignee Address: US CA Milpitas
- Agency: Rutan & Tucker, LLP
- Main IPC: G06F21/55
- IPC: G06F21/55 ; G06F21/53 ; H04L29/06

Abstract:
According to one embodiment, a system comprising a dynamic analysis server comprising one or more virtual machines is disclosed, wherein the one or more virtual machines may be configured to execute certain event logic with respect to a loaded module. The virtual machines may be communicatively coupled to a virtual machine manager and a database; and rule-matching logic comprising detection logic, wherein the detection logic is configured to determine (1) whether an access source is attempting to access a protected region such as a page guarded area; and (2) determine whether the access source is from the heap. The system further comprises reporting logic that is configured to generate an alert so as to notify a user and/or network administrator of a probable application-execution hijacking attack.
Information query