Invention Grant
- Patent Title: Systems and methods for identifying malware injected into a memory of a computing device
-
Application No.: US17373001Application Date: 2021-07-12
-
Publication No.: US12079337B2Publication Date: 2024-09-03
- Inventor: Joseph W. Desimone
- Applicant: Endgame, Inc.
- Applicant Address: US VA Arlington
- Assignee: Endgame, Inc.
- Current Assignee: Endgame, Inc.
- Current Assignee Address: US CA Mountain View
- Agency: Quinn IP Law
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F21/57

Abstract:
In the embodiments described herein, a malicious code detection module identifies potentially malicious instructions in memory of a computing device. The malicious code detection module examines the call stack for each thread running within the operating system of the computing device. Within each call stack, the malicious code detection module identifies the originating module for each stack frame and determines whether the originating module is backed by an image on disk. If an originating module is not backed by an image on disk, the thread containing that originating module is flagged as potentially malicious, execution of the thread optionally is suspended, and an alert is generated for the user or administrator.
Public/Granted literature
- US20210342445A1 Systems and Methods for Identifying Malware Injected into a Memory of a Computing Device Public/Granted day:2021-11-04
Information query