Invention Grant
- Patent Title: Detecting malware via scanning for dynamically generated function pointers in memory
-
Application No.: US16805478Application Date: 2020-02-28
-
Publication No.: US11256808B2Publication Date: 2022-02-22
- Inventor: Robert Jung
- Applicant: Palo Alto Networks, Inc.
- Applicant Address: US CA Santa Clara
- Assignee: Palo Alto Networks, Inc.
- Current Assignee: Palo Alto Networks, Inc.
- Current Assignee Address: US CA Santa Clara
- Agency: Van Pelt, Yi & James LLP
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F21/52 ; G06F11/30

Abstract:
Techniques for detecting malware via scanning for dynamically generated function pointers in memory are disclosed. In some embodiments, a system/process/computer program product for detecting malware via scanning for dynamically generated function pointers in memory includes monitoring changes in memory during execution of a malware sample in a computing environment; detecting a dynamically generated function pointer in memory based on an analysis of the monitored changes in memory during execution of the malware sample in the computing environment; and generating a signature based on detection of the dynamically generated function pointer in memory, wherein the malware sample was determined to be malicious.
Information query