Invention Grant
- Patent Title: Probabilistic shellcode detection
- Patent Title (中): 概率shellcode检测
-
Application No.: US12103498Application Date: 2008-04-15
-
Publication No.: US08549624B2Publication Date: 2013-10-01
- Inventor: Christoph Alme
- Applicant: Christoph Alme
- Applicant Address: US CA Santa Clara
- Assignee: Mcafee, Inc.
- Current Assignee: Mcafee, Inc.
- Current Assignee Address: US CA Santa Clara
- Agency: Wong, Cabello, Lutsch, Rutherford & Brucculeri, LLP
- Main IPC: G06F11/00
- IPC: G06F11/00

Abstract:
Various embodiments include a method of detecting shell code in an arbitrary file comprising determining where one or more candidate areas exist within an arbitrary file, searching at least one nearby area surrounding each of the one or more candidate areas within the arbitrary file for an instruction candidate, and calculating for any such instruction candidate a statistical probability based on a disassembly of instructions starting at a found offset for the instruction candidate that the disassembled instructions are shellcode.
Public/Granted literature
- US20100031359A1 PROBABILISTIC SHELLCODE DETECTION Public/Granted day:2010-02-04
Information query