- Patent Title: Detecting malware by monitoring execution of a configured process
-
Application No.: US15249366Application Date: 2016-08-27
-
Publication No.: US10515213B2Publication Date: 2019-12-24
- Inventor: Adrian Emil Stepan , Adrian M. Marinescu
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/56 ; G06F21/53 ; G06F21/55 ; G06F21/54

Abstract:
Described herein are various technologies pertaining detecting malware by monitoring execution of an instrumented process. An anti-malware engine can observe code obfuscation, suspicious patterns and/or behavior upon scanning a computer file. Based upon this observation, evidence can be submitted to a service (e.g., cloud-based service) and, in response, configuration setting(s) for restraining, containing and/or instrumenting a process for executing the file and/or instrumenting a process into which the file is loaded can be received. The configured process can be monitored. Based upon this monitoring, an action can be taken including determining the file to comprise malware and terminating the process. Upon detecting malware, a detection report, and a copy of the computer file, can be sent to a service (e.g., cloud-based). The service can independently verify that the reported file is malicious, and can protect other machines from executing or loading the same malicious file.
Public/Granted literature
- US20180060579A1 Detecting Malware by Monitoring Execution of a Configured Process Public/Granted day:2018-03-01
Information query