首页> 外国专利> SYSTÈME ET PROCÉDÉ DE DÉTECTION DE CODE MALVEILLANT DANS L'ESPACE D'ADRESSE DE PROCESSUS

SYSTÈME ET PROCÉDÉ DE DÉTECTION DE CODE MALVEILLANT DANS L'ESPACE D'ADRESSE DE PROCESSUS

摘要

Disclosed are methods and systems for detecting malicious codes in the address space of processes. The described method detects a launching of a process from an executable file executing on a computer, detects access to a address within a memory area in an address space of the trusted process, wherein the memory area is a memory area that lies outside the boundaries of the trusted executable image representing the executable file and is an executable memory area, analyzes memory areas within a vicinity of the address space to determine whether another executable image is located in the memory areas, analyzing the another executable image to determine whether the other executable image contains malicious code, concluding malicious code is contained in the address space of the trusted process when the another executable image contains malicious code and performing one of removing, halting or quaranting the malicious code from the address space.

著录项

  • 公开/公告号EP3462358B1

    专利类型

  • 公开/公告日2020.05.13

    原文格式PDF

  • 申请/专利权人 AO Kaspersky Lab;

    申请/专利号EP18191632.1

  • 发明设计人

    申请日2018.08.30

  • 分类号

  • 国家 EP

  • 入库时间 2022-08-21 10:52:14

相似文献

  • 专利
  • 外文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号