Invention Grant
- Patent Title: Segregating executable files exhibiting network activity
-
Application No.: US16110696Application Date: 2018-08-23
-
Publication No.: US10599846B2Publication Date: 2020-03-24
- Inventor: Neeraj Thakar , Amit Malik
- Applicant: McAfee, LLC
- Applicant Address: US CA Santa Clara
- Assignee: MCAFEE, LLC
- Current Assignee: MCAFEE, LLC
- Current Assignee Address: US CA Santa Clara
- Agency: Hanley, Flight & Zimmerman, LLC
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/56

Abstract:
Systems, computer readable media, apparatuses, and methods are disclosed for segregating executable files exhibiting network activity. An example apparatus includes at least one processor and memory including instructions which, when executed, cause the at least one processor to launch an executable file in a segmented portion of a computing system to load one or more dynamically linked libraries (DLLs) associated with the executable file into a process environment block (PEB) of the segmented portion, enumerate the PEB to generate an address list of the one or more DLLs, scan the one or more DLLs to determine whether the one or more DLLs are to perform network activity, and perform malware analysis on the executable file when at least one of the one or more DLLs are to perform network activity.
Public/Granted literature
- US20190005243A1 SEGREGATING EXECUTABLE FILES EXHIBITING NETWORK ACTIVITY Public/Granted day:2019-01-03
Information query