Invention Grant
- Patent Title: Method and apparatus for detecting shellcode
- Patent Title (中): 检测shellcode的方法和装置
-
Application No.: US10172138Application Date: 2002-06-13
-
Publication No.: US07904955B1Publication Date: 2011-03-08
- Inventor: Zheng Bu , Fengmin Gong
- Applicant: Zheng Bu , Fengmin Gong
- Applicant Address: US CA Santa Clara
- Assignee: McAfee, Inc.
- Current Assignee: McAfee, Inc.
- Current Assignee Address: US CA Santa Clara
- Agency: Zilka-Kotab, PC
- Main IPC: G06F12/14
- IPC: G06F12/14 ; G06F12/16 ; G08B23/00

Abstract:
The invention is a method and apparatus for detecting shellcode such that a set of computer instructions is scanned for the presence of a null operation instruction. The computer instructions are also examined for the presence of a system call instruction, and reviewed for the presence of a decoder instruction set. A null operation weight value is then determined corresponding to the null operation instruction. Also assessed is a system call weight value corresponding to the system call instruction. In addition, a decoder weight value is calculated corresponding to the decoder instruction set. The null operation weight value, the system call weight value, and the decoder weight value are then analyzed to identify a shellcode.
Information query