Invention Grant
- Patent Title: Shellcode detection
-
Application No.: US14311000Application Date: 2014-06-20
-
Publication No.: US09973531B1Publication Date: 2018-05-15
- Inventor: Emmanuel Thioux
- Applicant: FireEye, Inc.
- Applicant Address: US CA Milpitas
- Assignee: FireEye, Inc.
- Current Assignee: FireEye, Inc.
- Current Assignee Address: US CA Milpitas
- Agency: Rutan & Tucker, LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F9/455

Abstract:
According to one embodiment, a threat detection system is integrated with at least a dynamic analysis engine. The dynamic analysis engine is configured to automatically determine whether one or more objects included in received network traffic contains a heap spray attack. Upon detection of a potential heap spray attack, the dynamic analysis engine may copy potential shellcode within an object included in the received network traffic, insert the copy of the potential shellcode into a second region of allocated memory and analyze the execution of the potential shellcode to determine whether characteristics associated with an exploit are present.
Information query