Patent №
US 9,787,699
Granted
2017-10-10
Filed 2016
Owner
F-SECURE CORPORATION
Lab
—
AI components
1
hardware
Assignment
Recorded
Dataset
AIPD
2023_r1 edition
Application
15334775
There is provided a malware analysis method including at a computer device having an operating system and a memory: collecting Dynamic Link Library (DLL) data under a system folder, the data including at least the DLL name and all pairs of exported function names and function addresses relative to the starting address of the DLL once it has been loaded into memory; comparing the two least significant bytes of the collected function addresses with the two least significant bytes of absolute virtual addresses in a memory dump; deducing a list of potential targets for API function calls when there is a match between the compared two least significant bytes of the collected function addresses and the absolute virtual addresses; and quarantining or deleting malware from which the suspicious API function calls originated.
AI classification
Ownership
F-SECURE CORPORATION
assignment · 401400040
Assignors
SUOMINEN, MIKKO
On an employer assignment, the assignors are typically the inventors.