Invention Grant
- Patent Title: Bypassing software services to detect malware
- Patent Title (中): 绕过软件服务来检测恶意软件
-
Application No.: US11344360Application Date: 2006-01-30
-
Publication No.: US07757290B2Publication Date: 2010-07-13
- Inventor: Mihai Costea , Yun Lin
- Applicant: Mihai Costea , Yun Lin
- Applicant Address: US WA Redmond
- Assignee: Microsoft Corporation
- Current Assignee: Microsoft Corporation
- Current Assignee Address: US WA Redmond
- Agency: Workman Nydegger
- Main IPC: G06F17/00
- IPC: G06F17/00 ; G06F12/14 ; G06F12/16 ; G08B23/00

Abstract:
A method, apparatus, and computer readable medium are provided by aspects of the present invention to determine whether a malware is resident on a host computer. In one embodiment, a method determines whether data that is characteristic of malware is loaded in the system memory of a host computer. More specifically, the method includes causing a device communicatively connected to a host computer to issue a request to obtain data loaded in the system memory. Then, when the requested data is received, a determination is made regarding whether the data is characteristic of malware. Since, the method causes data to be obtained directly from system memory without relying on software services on the host computer, malware that employs certain stealth techniques will be identified.
Public/Granted literature
- US20070180529A1 Bypassing software services to detect malware Public/Granted day:2007-08-02
Information query