Invention Grant
- Patent Title: Malware detection through symbol whitelisting
- Patent Title (中): 通过符号白名单检测恶意软件
-
Application No.: US12130206Application Date: 2008-05-30
-
Publication No.: US08176554B1Publication Date: 2012-05-08
- Inventor: Mark Kennedy
- Applicant: Mark Kennedy
- Applicant Address: US CA Cupertino
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Cupertino
- Agency: Fenwick & West LLP
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A security module identifies symbols within an executable file. The security module compares these identified symbols to a set of symbols expected to be present in a legitimate executable file. Based at least in part on an identified symbol not being within the set of expected symbols, the security module determines that the executable file poses a heightened security risk. In one embodiment, a remediation module takes an appropriate response to prevent potential malware exploits by the executable file.
Information query