METHOD OF GENERATING IN-KERNEL HOOK POINT CANDIDATES TO DETECT ROOTKITS AND THE SYSTEM THEREOF

Patent №

US 9,747,452

Granted

2017-08-29

Filed 2014

Owner

NATIONAL CHIAO TUNG UNIVERSITY

Lab

AI components

1

hardware

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

14512420

A method for determining whether a to-be-tested program contains malicious behavior is disclosed. The method includes steps of providing an emulator having a kernel and a plurality of installed hook points, wherein the kernel has a plurality of in-kernel functions; executing the to-be-tested program in the emulator dynamically to invoke the plurality of installed hook points to obtain a specific in-kernel function set from the plurality of in-kernel functions; and determining whether the to-be-tested program contains instructions for malicious behavior based on an invocation sequence of the specific in-kernel function set.

AI hardwareG06F 21/577G06F 21/561

AI classification

AI hardware1.00
Knowledge representation0.40
Natural language0.08
Planning0.08
Vision0.03
Evolutionary computation0.00
Machine learning0.00
Speech0.00

Ownership

NATIONAL CHIAO TUNG UNIVERSITY

assignment · 370530911

Assignors

WANG, CHI-WEI, CHEN, CHONG-KUAN, WANG, CHIA-WEI, SHIEH, SHIUHPYNG

On an employer assignment, the assignors are typically the inventors.

© 2026 NYSGPT2525 LLC