SYSTEM AND METHOD FOR DETECTING MALICIOUS CODE IN RANDOM ACCESS MEMORY

Disclosed are system and method for detecting malicious code in random access memory. An exemplary method comprises: detecting, by a hardware processor, a process of an untrusted program on the computer; identifying, by the hardware processor, function calls made by the process of the untrusted prog...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: NAZAROV, Denis A, MONASTYRSKY, Alexey V, PAVLYUSHCHIK, Mikhail A
Format: Patent
Sprache:eng ; fre ; ger
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
container_end_page
container_issue
container_start_page
container_title
container_volume
creator NAZAROV, Denis A
MONASTYRSKY, Alexey V
PAVLYUSHCHIK, Mikhail A
description Disclosed are system and method for detecting malicious code in random access memory. An exemplary method comprises: detecting, by a hardware processor, a process of an untrusted program on the computer; identifying, by the hardware processor, function calls made by the process of the untrusted program, including inter-process function calls made by the process to a destination process; determining, by the hardware processor, whether to perform malware analysis of a code in an address space of the destination process that was subject of an inter-process function call made by the process of the untrusted program; and when it is determined to perform malware analysis, analyzing the code in an address space of the destination process that was subject of an inter-process function call made by the process of the untrusted program using antivirus software executable by the hardware processor.
format Patent
fullrecord <record><control><sourceid>epo_EVB</sourceid><recordid>TN_cdi_epo_espacenet_EP3113063B1</recordid><sourceformat>XML</sourceformat><sourcesystem>PC</sourcesystem><sourcerecordid>EP3113063B1</sourcerecordid><originalsourceid>FETCH-epo_espacenet_EP3113063B13</originalsourceid><addsrcrecordid>eNrjZHALjgwOcfVVcPRzUfB1DfHwd1Fw8w9ScHENcXUO8fRzV_B19PF09vQPDVZw9ndxVfD0UwgCqvUH6nB2dg0OBmry9Q-K5GFgTUvMKU7lhdLcDApuriHOHrqpBfnxqcUFicmpeakl8a4BxoaGxgZmxk6GxkQoAQA4uCuU</addsrcrecordid><sourcetype>Open Access Repository</sourcetype><iscdi>true</iscdi><recordtype>patent</recordtype></control><display><type>patent</type><title>SYSTEM AND METHOD FOR DETECTING MALICIOUS CODE IN RANDOM ACCESS MEMORY</title><source>esp@cenet</source><creator>NAZAROV, Denis A ; MONASTYRSKY, Alexey V ; PAVLYUSHCHIK, Mikhail A</creator><creatorcontrib>NAZAROV, Denis A ; MONASTYRSKY, Alexey V ; PAVLYUSHCHIK, Mikhail A</creatorcontrib><description>Disclosed are system and method for detecting malicious code in random access memory. An exemplary method comprises: detecting, by a hardware processor, a process of an untrusted program on the computer; identifying, by the hardware processor, function calls made by the process of the untrusted program, including inter-process function calls made by the process to a destination process; determining, by the hardware processor, whether to perform malware analysis of a code in an address space of the destination process that was subject of an inter-process function call made by the process of the untrusted program; and when it is determined to perform malware analysis, analyzing the code in an address space of the destination process that was subject of an inter-process function call made by the process of the untrusted program using antivirus software executable by the hardware processor.</description><language>eng ; fre ; ger</language><subject>CALCULATING ; COMPUTING ; COUNTING ; ELECTRIC COMMUNICATION TECHNIQUE ; ELECTRIC DIGITAL DATA PROCESSING ; ELECTRICITY ; PHYSICS ; TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION</subject><creationdate>2017</creationdate><oa>free_for_read</oa><woscitedreferencessubscribed>false</woscitedreferencessubscribed></display><links><openurl>$$Topenurl_article</openurl><openurlfulltext>$$Topenurlfull_article</openurlfulltext><thumbnail>$$Tsyndetics_thumb_exl</thumbnail><linktohtml>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&amp;date=20170913&amp;DB=EPODOC&amp;CC=EP&amp;NR=3113063B1$$EHTML$$P50$$Gepo$$Hfree_for_read</linktohtml><link.rule.ids>230,308,776,881,25544,76293</link.rule.ids><linktorsrc>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&amp;date=20170913&amp;DB=EPODOC&amp;CC=EP&amp;NR=3113063B1$$EView_record_in_European_Patent_Office$$FView_record_in_$$GEuropean_Patent_Office$$Hfree_for_read</linktorsrc></links><search><creatorcontrib>NAZAROV, Denis A</creatorcontrib><creatorcontrib>MONASTYRSKY, Alexey V</creatorcontrib><creatorcontrib>PAVLYUSHCHIK, Mikhail A</creatorcontrib><title>SYSTEM AND METHOD FOR DETECTING MALICIOUS CODE IN RANDOM ACCESS MEMORY</title><description>Disclosed are system and method for detecting malicious code in random access memory. An exemplary method comprises: detecting, by a hardware processor, a process of an untrusted program on the computer; identifying, by the hardware processor, function calls made by the process of the untrusted program, including inter-process function calls made by the process to a destination process; determining, by the hardware processor, whether to perform malware analysis of a code in an address space of the destination process that was subject of an inter-process function call made by the process of the untrusted program; and when it is determined to perform malware analysis, analyzing the code in an address space of the destination process that was subject of an inter-process function call made by the process of the untrusted program using antivirus software executable by the hardware processor.</description><subject>CALCULATING</subject><subject>COMPUTING</subject><subject>COUNTING</subject><subject>ELECTRIC COMMUNICATION TECHNIQUE</subject><subject>ELECTRIC DIGITAL DATA PROCESSING</subject><subject>ELECTRICITY</subject><subject>PHYSICS</subject><subject>TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION</subject><fulltext>true</fulltext><rsrctype>patent</rsrctype><creationdate>2017</creationdate><recordtype>patent</recordtype><sourceid>EVB</sourceid><recordid>eNrjZHALjgwOcfVVcPRzUfB1DfHwd1Fw8w9ScHENcXUO8fRzV_B19PF09vQPDVZw9ndxVfD0UwgCqvUH6nB2dg0OBmry9Q-K5GFgTUvMKU7lhdLcDApuriHOHrqpBfnxqcUFicmpeakl8a4BxoaGxgZmxk6GxkQoAQA4uCuU</recordid><startdate>20170913</startdate><enddate>20170913</enddate><creator>NAZAROV, Denis A</creator><creator>MONASTYRSKY, Alexey V</creator><creator>PAVLYUSHCHIK, Mikhail A</creator><scope>EVB</scope></search><sort><creationdate>20170913</creationdate><title>SYSTEM AND METHOD FOR DETECTING MALICIOUS CODE IN RANDOM ACCESS MEMORY</title><author>NAZAROV, Denis A ; MONASTYRSKY, Alexey V ; PAVLYUSHCHIK, Mikhail A</author></sort><facets><frbrtype>5</frbrtype><frbrgroupid>cdi_FETCH-epo_espacenet_EP3113063B13</frbrgroupid><rsrctype>patents</rsrctype><prefilter>patents</prefilter><language>eng ; fre ; ger</language><creationdate>2017</creationdate><topic>CALCULATING</topic><topic>COMPUTING</topic><topic>COUNTING</topic><topic>ELECTRIC COMMUNICATION TECHNIQUE</topic><topic>ELECTRIC DIGITAL DATA PROCESSING</topic><topic>ELECTRICITY</topic><topic>PHYSICS</topic><topic>TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION</topic><toplevel>online_resources</toplevel><creatorcontrib>NAZAROV, Denis A</creatorcontrib><creatorcontrib>MONASTYRSKY, Alexey V</creatorcontrib><creatorcontrib>PAVLYUSHCHIK, Mikhail A</creatorcontrib><collection>esp@cenet</collection></facets><delivery><delcategory>Remote Search Resource</delcategory><fulltext>fulltext_linktorsrc</fulltext></delivery><addata><au>NAZAROV, Denis A</au><au>MONASTYRSKY, Alexey V</au><au>PAVLYUSHCHIK, Mikhail A</au><format>patent</format><genre>patent</genre><ristype>GEN</ristype><title>SYSTEM AND METHOD FOR DETECTING MALICIOUS CODE IN RANDOM ACCESS MEMORY</title><date>2017-09-13</date><risdate>2017</risdate><abstract>Disclosed are system and method for detecting malicious code in random access memory. An exemplary method comprises: detecting, by a hardware processor, a process of an untrusted program on the computer; identifying, by the hardware processor, function calls made by the process of the untrusted program, including inter-process function calls made by the process to a destination process; determining, by the hardware processor, whether to perform malware analysis of a code in an address space of the destination process that was subject of an inter-process function call made by the process of the untrusted program; and when it is determined to perform malware analysis, analyzing the code in an address space of the destination process that was subject of an inter-process function call made by the process of the untrusted program using antivirus software executable by the hardware processor.</abstract><oa>free_for_read</oa></addata></record>
fulltext fulltext_linktorsrc
identifier
ispartof
issn
language eng ; fre ; ger
recordid cdi_epo_espacenet_EP3113063B1
source esp@cenet
subjects CALCULATING
COMPUTING
COUNTING
ELECTRIC COMMUNICATION TECHNIQUE
ELECTRIC DIGITAL DATA PROCESSING
ELECTRICITY
PHYSICS
TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION
title SYSTEM AND METHOD FOR DETECTING MALICIOUS CODE IN RANDOM ACCESS MEMORY
url https://sfx.bib-bvb.de/sfx_tum?ctx_ver=Z39.88-2004&ctx_enc=info:ofi/enc:UTF-8&ctx_tim=2025-01-27T12%3A53%3A41IST&url_ver=Z39.88-2004&url_ctx_fmt=infofi/fmt:kev:mtx:ctx&rfr_id=info:sid/primo.exlibrisgroup.com:primo3-Article-epo_EVB&rft_val_fmt=info:ofi/fmt:kev:mtx:patent&rft.genre=patent&rft.au=NAZAROV,%20Denis%20A&rft.date=2017-09-13&rft_id=info:doi/&rft_dat=%3Cepo_EVB%3EEP3113063B1%3C/epo_EVB%3E%3Curl%3E%3C/url%3E&disable_directlink=true&sfx.directlink=off&sfx.report_link=0&rft_id=info:oai/&rft_id=info:pmid/&rfr_iscdi=true