Invention Grant
- Patent Title: Malicious software detection based on API trust
-
Application No.: US15952980Application Date: 2018-04-13
-
Publication No.: US11544379B2Publication Date: 2023-01-03
- Inventor: Andrew L. Sandoval , David Alan Myers , John R. Shaw, II , Eric Klonowski
- Applicant: Webroot Inc.
- Applicant Address: US CO Broomfield
- Assignee: Webroot Inc.
- Current Assignee: Webroot Inc.
- Current Assignee Address: US CO Broomfield
- Agency: Sprinkle IP Law Group
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/56 ; G06F21/55

Abstract:
Examples of the present disclosure describe systems and methods for malicious software detection based on API trust. In an example, a set of software instructions executed by a computing device may call an API. A hook may be generated on the API, such that a threat processor may receive an indication when the API is called. Accordingly, the threat processor may generate a trust metric based on the execution of the set of software instructions, which may be used to determine whether the set of software instructions poses a potential threat. For example, one or more call stack frames may be evaluated to determine whether a return address is preceded by a call instruction, whether the return address is associated with a set of software instructions or memory associated with a set of software instructions, and/or whether the set of software instructions satisfies a variety of security criteria.
Public/Granted literature
- US20190318090A1 MALICIOUS SOFTWARE DETECTION BASED ON API TRUST Public/Granted day:2019-10-17
Information query