Invention Grant
- Patent Title: Malware detection and classification based on memory semantic analysis
-
Application No.: US15335224Application Date: 2016-10-26
-
Publication No.: US10417420B2Publication Date: 2019-09-17
- Inventor: Jie Zhang
- Applicant: Fortinet, Inc.
- Applicant Address: US CA Sunnyvale
- Assignee: Fortinet, Inc.
- Current Assignee: Fortinet, Inc.
- Current Assignee Address: US CA Sunnyvale
- Agency: Jaffery Watson Mendosa & Hamilton, LLP
- Main IPC: G06F21/56
- IPC: G06F21/56

Abstract:
Systems and methods for malware detection and classification based on semantic analysis of memory dumps of malware are provided. According to one embodiment, a malware detector running within a computer system causes a sample file to be executed within a target process that is monitored by a process monitor of the malware detector. One or more memory dumps associated with the sample file are captured by the process monitor. A determination regarding whether the sample file represents malware is made by the malware detector by analyzing characteristics of at least one memory dump of the one or more memory dumps with reference to characteristics of memory dumps of a plurality of known malware samples.
Public/Granted literature
- US20180114018A1 MALWARE DETECTION AND CLASSIFICATION BASED ON MEMORY SEMANTIC ANALYSIS Public/Granted day:2018-04-26
Information query