Invention Grant
- Patent Title: System and method for detection of heap spray attack
-
Application No.: US14745300Application Date: 2015-06-19
-
Publication No.: US09881153B2Publication Date: 2018-01-30
- Inventor: Falcon Momot
- Applicant: Leviathan, Inc.
- Applicant Address: US WA Seattle
- Assignee: Leviathan, Inc.
- Current Assignee: Leviathan, Inc.
- Current Assignee Address: US WA Seattle
- Agent Vernon Francissen
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/55

Abstract:
Methods, systems and media are shown for detecting a heap spray event involving examining user allocated portions of heap memory for a process image, determining a level of entropy for the user allocated portions, and, if the level of entropy is below a threshold, performing secondary heuristics, and detecting a heap spray event based on results of the secondary heuristics. In some examples, performing the secondary heuristics may include analyzing a pattern of memory allocation for the user allocated portions, analyzing data content of the user allocated portions of heap memory, or analyzing a heap allocation size for the user allocated portions of heap memory.
Public/Granted literature
- US20160004861A1 System and Method for Detection of Heap Spray Attack Public/Granted day:2016-01-07
Information query