System and Method for Validating In-Memory Integrity of Executable Files to Identify Malicious Activity
Patent №
US 11,675,905
Granted
2023-06-13
Filed 2021
Owner
ENDGAME, INC.
Lab
—
AI components
1
hardware
Assignment
Recorded
Dataset
AIPD
2023_r1 edition
Application
17501965
A malicious code detection module is presented to identify potentially malicious instructions in a volatile memory of a computing device before the instructions are executed. The malicious code detection module identifies an executable file, including an .exe file, in memory, validates one or more components of the executable file against the same file stored in non-volatile storage, wherein the validation accounts for the unpacking of the executable file, and issues an alert if the validation fails.
AI classification
Ownership
ENDGAME, INC.
assignment · 581300323
Assignors
DESIMONE, JOSEPH W.
On an employer assignment, the assignors are typically the inventors.