MALWARE INVESTIGATION BY ANALYZING COMPUTER MEMORY

Patent №

US 8,566,944

Granted

2013-10-22

Filed 2010

Owner

MICROSOFT CORPORATION

AI components

2

kr · hardware

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

12767810

Technology is described for malware investigation by analyzing computer memory in a computing device. The method can include performing static analysis on code for a software environment to form an extended type graph. A raw memory snapshot of the computer memory can be obtained at runtime. The raw memory snapshot may include the software environment executing on the computing device. Dynamic data structures can be found in the raw memory snapshot using the extended type graph to form an object graph. An authorized memory area can be defined having executable code, static data structures, and dynamic data structures. Implicit and explicit function pointers can be identified. The function pointers can be checked to validate that the function pointers reference a valid memory location in the authorized memory area and whether the computer memory is uncompromised.

AI classification

Knowledge representation1.00
AI hardware0.83
Planning0.02
Vision0.00
Evolutionary computation0.00
Natural language0.00
Machine learning0.00
Speech0.00

Ownership

MICROSOFT CORPORATION

assignment · 242910296

Assignors

PEINADO, MARCUS, CUI, WEIDONG

On an employer assignment, the assignors are typically the inventors.

© 2026 NYSGPT2525 LLC