×

PROBABILISTIC SHELLCODE DETECTION

  • US 20100031359A1
  • Filed: 04/15/2008
  • Published: 02/04/2010
  • Est. Priority Date: 04/14/2008
  • Status: Active Grant
First Claim
Patent Images

1. A method of detecting shell code in an arbitrary file comprising:

  • determining where one or more candidate areas exist within an arbitrary file;

    searching at least one nearby area surrounding each of the one or more candidate areas within the arbitrary file for an instruction candidate; and

    calculating for any such instruction candidate a statistical probability based on a disassembly of instructions starting at a found offset for the instruction candidate that the disassembled instructions are shellcode.

View all claims
  • 12 Assignments
Timeline View
Assignment View
    ×
    ×