Invention Grant
- Patent Title: Accelerated code injection detection using operating system controlled memory attributes
-
Application No.: US15640192Application Date: 2017-06-30
-
Publication No.: US10664594B2Publication Date: 2020-05-26
- Inventor: Abhishek Kumar Singh , Aditya Joshi , Freddie L. Aaron , Peter A. Loveless , Tino Morenz
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Agency: Fiala & Weaver P.L.L.C.
- Main IPC: G06F12/00
- IPC: G06F12/00 ; G06F21/56 ; G06F12/14 ; G06F21/79 ; G06F12/1009

Abstract:
Methods for accelerated code injection detection using operating system controlled memory attributes are performed by systems and apparatuses. The methods optimize search operations for memory segments in system and virtual memories by searching for segment attributes. A set of memory segments is determined wherein each memory segment in the set includes specific attributes. The memory segments in the set are ranked for a threat level based on segment attribute. The threat level is used to determine subsequent actions including providing indications of the memory segments in the set and initiating execution of an anti-malware application. Relevant segment attributes used for the segment search can be dynamically updated in an attribute list. Segment attributes of a segment can be determined by accessing a memory manager of an operating system via an API.
Public/Granted literature
- US20190005236A1 ACCELERATED CODE INJECTION DETECTION USING OPERATING SYSTEM CONTROLLED MEMORY ATTRIBUTES Public/Granted day:2019-01-03
Information query