- Patent Title: Detecting malicious software by inspecting table look-aside buffers
-
Application No.: US15841033Application Date: 2017-12-13
-
Publication No.: US10706150B2Publication Date: 2020-07-07
- Inventor: Shlomi Boutnaru
- Applicant: PayPal, Inc.
- Applicant Address: US CA San Jose
- Assignee: PayPal, Inc.
- Current Assignee: PayPal, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Haynes and Boone, LLP
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F21/55 ; G06F12/1009 ; G06F12/1027 ; G06F21/12 ; G06F21/78

Abstract:
Systems and methods that detect presence of malicious software while comparing address mappings in multiple table look-aside buffers are provided. Address mappings in an instruction table look-aside buffer (ITLB) and a data table look-aside buffer (DTLB) may be scanned with each address mapping including a mapping between a virtual page in a virtual memory and a frame in a physical memory of a computing device. A discrepancy between an address mapping in the ITLB and an address mapping in the DTLB can be identified. Based on the discrepancy, a process associated with the mapping may then be identified as a malicious process.
Public/Granted literature
- US20190180031A1 DETECTING MALICIOUS SOFTWARE BY INSPECTING TABLE LOOK-ASIDE BUFFERS Public/Granted day:2019-06-13
Information query