Invention Grant
US08813227B2 System and method for below-operating system regulation and control of self-modifying code
有权
系统和方法,用于操作系统调节和自修改代码的控制
- Patent Title: System and method for below-operating system regulation and control of self-modifying code
- Patent Title (中): 系统和方法,用于操作系统调节和自修改代码的控制
-
Application No.: US13074831Application Date: 2011-03-29
-
Publication No.: US08813227B2Publication Date: 2014-08-19
- Inventor: Ahmed Said Sallam
- Applicant: Ahmed Said Sallam
- Applicant Address: US CA Santa Clara
- Assignee: McAfee, Inc.
- Current Assignee: McAfee, Inc.
- Current Assignee Address: US CA Santa Clara
- Agency: Baker Botts L.L.P.
- Main IPC: G06F21/06
- IPC: G06F21/06 ; G06F12/14

Abstract:
A system for securing an electronic device may include a memory, a processor; one or more operating systems residing in the memory for execution by the processor; and a security agent configured to execute on the electronic device at a level below all of the operating systems of the electronic device accessing the memory. The security agent may be further configured to: (i) trap attempted accesses to the memory, wherein each of such attempted accesses may, individually or in the aggregate, indicate the presence of self-modifying malware; (ii) in response to trapping each attempted access to the memory, record information associated with the attempted access in a history; and (iii) in response to a triggering attempted access associated with a particular memory location, analyze information in the history associated with the particular memory location to determine if suspicious behavior has occurred with respect to the particular memory location.
Public/Granted literature
- US20120255012A1 SYSTEM AND METHOD FOR BELOW-OPERATING SYSTEM REGULATION AND CONTROL OF SELF-MODIFYING CODE Public/Granted day:2012-10-04
Information query