×

COMPARING STRUCTURAL INFORMATION OF A SNAPSHOT OF SYSTEM MEMORY

  • US 20180218153A1
  • Filed: 01/31/2017
  • Published: 08/02/2018
  • Est. Priority Date: 01/31/2017
  • Status: Active Grant
First Claim
Patent Images

1. A non-transitory computer readable storage medium storing instructions executable by a processor to:

  • obtain structural information of a process extracted from a snapshot of system memory wherein the structural information includes a hash or fuzzy hash of each executable region of the process;

    compare the structural information of the process with a process model which includes hashes or fuzzy hashes of executable regions of the same process in a previous snapshot of system memory;

    determine there is a structural anomaly in response to a determination that the structural information includes a hash or fuzzy hash which is inconsistent with the process model; and

    in response to determining that there is a structural anomaly, generate a malware alert.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×