Invention Grant
US08813227B2 System and method for below-operating system regulation and control of self-modifying code 有权
系统和方法,用于操作系统调节和自修改代码的控制

  • Patent Title: System and method for below-operating system regulation and control of self-modifying code
  • Patent Title (中): 系统和方法,用于操作系统调节和自修改代码的控制
  • Application No.: US13074831
    Application Date: 2011-03-29
  • Publication No.: US08813227B2
    Publication Date: 2014-08-19
  • Inventor: Ahmed Said Sallam
  • Applicant: Ahmed Said Sallam
  • Applicant Address: US CA Santa Clara
  • Assignee: McAfee, Inc.
  • Current Assignee: McAfee, Inc.
  • Current Assignee Address: US CA Santa Clara
  • Agency: Baker Botts L.L.P.
  • Main IPC: G06F21/06
  • IPC: G06F21/06 G06F12/14
System and method for below-operating system regulation and control of self-modifying code
Abstract:
A system for securing an electronic device may include a memory, a processor; one or more operating systems residing in the memory for execution by the processor; and a security agent configured to execute on the electronic device at a level below all of the operating systems of the electronic device accessing the memory. The security agent may be further configured to: (i) trap attempted accesses to the memory, wherein each of such attempted accesses may, individually or in the aggregate, indicate the presence of self-modifying malware; (ii) in response to trapping each attempted access to the memory, record information associated with the attempted access in a history; and (iii) in response to a triggering attempted access associated with a particular memory location, analyze information in the history associated with the particular memory location to determine if suspicious behavior has occurred with respect to the particular memory location.
Information query
Patent Agency Ranking
0/0