Invention Grant
- Patent Title: System and method for detection of malicious code in the address space of processes
-
Application No.: US15925920Application Date: 2018-03-20
-
Publication No.: US10691800B2Publication Date: 2020-06-23
- Inventor: Mikhail A. Pavlyushchik
- Applicant: AO Kaspersky Lab
- Applicant Address: RU Moscow
- Assignee: AO Kaspersky Lab
- Current Assignee: AO Kaspersky Lab
- Current Assignee Address: RU Moscow
- Agency: Arent Fox LLP
- Agent Michael Fainberg
- Priority: com.zzzhc.datahub.patent.etl.us.BibliographicData$PriorityClaim@1ead1c27
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/56 ; G06F21/52

Abstract:
Disclosed are methods and systems for detecting malicious codes in the address space of processes. The described method detects a launching of a process from an executable file executing on a computer, detects access to a address within a memory area in an address space of the trusted process, wherein the memory area is a memory area that lies outside the boundaries of the trusted executable image representing the executable file and is an executable memory area, analyzes memory areas within a vicinity of the address space to determine whether another executable image is located in the memory areas, analyzing the another executable image to determine whether the other executable image contains malicious code, concluding malicious code is contained in the address space of the trusted process when the another executable image contains malicious code and performing one of removing, halting or quaranting the malicious code from the address space.
Public/Granted literature
- US20190102552A1 SYSTEM AND METHOD FOR DETECTION OF MALICIOUS CODE IN THE ADDRESS SPACE OF PROCESSES Public/Granted day:2019-04-04
Information query