Visual classification according to binary memory dump
Abstract:
There is disclosed in one example a method of detecting computer malware, including: receiving a binary object for analysis; allocating the binary object to a sandbox; within the sandbox, loading the binary object into an executable memory region; performing a memory dump of the executable memory region; and analyzing the memory dump for malware characteristics.
Public/Granted literature
Information query
Patent Agency Ranking
0/0