Invention Grant
- Patent Title: System and method for identifying and mitigating cyberattacks through malicious position-independent code execution
-
Application No.: US16586794Application Date: 2019-09-27
-
Publication No.: US11886585B1Publication Date: 2024-01-30
- Inventor: Stephen Davis
- Applicant: FireEye, Inc.
- Applicant Address: US CA Milpitas
- Assignee: Musarubra US LLC
- Current Assignee: Musarubra US LLC
- Current Assignee Address: US TX Plano
- Agency: Rutan & Tucker, LLP
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F11/32 ; G06F21/57

Abstract:
A computing system including a processor and a memory, which includes a first memory region operating as a kernel space and a second memory region operating as a user space. Maintained within the kernel space, a first logic unit receives a notification identifying a newly created thread and extracts at least meta-information associated with the newly created thread. Maintained within the user space, a second logic unit receives at least the meta-information associated with the newly created thread and conducts analytics on at least the meta-information to attempt to classify the newly created thread. An alert is generated by the second logic unit upon classifying the newly created thread as a cyberattack associated with a malicious position independent code execution based at least on results of the analytics associated with the meta-information associated with the newly created thread.
Information query