Invention Grant
- Patent Title: Identifying malware that employs stealth techniques
- Patent Title (中): 识别使用隐身技术的恶意软件
-
Application No.: US11263599Application Date: 2005-10-31
-
Publication No.: US07743418B2Publication Date: 2010-06-22
- Inventor: Neill Clift , Thushara K. Wijeratna
- Applicant: Neill Clift , Thushara K. Wijeratna
- Applicant Address: US WA Redmond
- Assignee: Microsoft Corporation
- Current Assignee: Microsoft Corporation
- Current Assignee Address: US WA Redmond
- Agency: Workman Nydegger
- Main IPC: G06F12/14
- IPC: G06F12/14 ; G06F7/04 ; G08B23/00

Abstract:
A method, software system, and computer-readable medium are provided for determining whether a malware that implements stealth techniques is resident on a computer. In one exemplary embodiment, a method is provided that obtains a first set of data that describes the processes that are reported as being active on the computer in a non-interrupt environment. Then, the method causes program execution to be interrupted at runtime so that an analysis of the active processes on the computer may be performed. After program execution is interrupted, a second set data that describes the processes that are reported as being active on the computer in a interrupt environment is obtained. By performing a comparison between the first and second sets of data, a determination may be made regarding whether the collected data contains inconsistencies that are characteristic of malware.
Public/Granted literature
- US20070101431A1 Identifying malware that employs stealth techniques Public/Granted day:2007-05-03
Information query