SYSTEM AND METHODS FOR ADVANCED MALWARE DETECTION THROUGH PLACEMENT OF TRANSITION EVENTS
Patent №
US 10,169,585
Granted
2019-01-01
Filed 2016
Owner
FIREEYE, INC.
Lab
—
AI components
1
hardware
Assignment
Recorded
Dataset
AIPD
2023_r1 edition
Application
15189993
A non-transitory storage medium including instructions that are executable by one or more processors to perform operations including instrumenting a VM is shown. The VM is used to process an object to determine whether the object is associated with malware. Logic within the VM analyzes memory allocated for a process within the VM for a point of interest (POI), the POI being an address of one of a set predetermined instructions likely to be associated with malware. The VMM detects a memory violation during processing of the object and responsive to detecting the memory violation, injects a transition event at the POI on the page on which the POI is located in memory. Further, responsive to detecting an attempted execution of the transition event, the VMM (i) emulates an instruction located at the POI, and (ii) the logic within the VM performs one or more malware detection routines.
AI classification
Ownership
FIREEYE, INC.
assignment · 389890310
Assignors
PILIPENKO, ALEX, HA, PHUNG-TE
On an employer assignment, the assignors are typically the inventors.