Invention Grant
- Patent Title: Execution profiling detection of malicious objects
-
Application No.: US14582163Application Date: 2014-12-23
-
Publication No.: US09934380B2Publication Date: 2018-04-03
- Inventor: Greg W. Dalcher , Koichi Yamada , Palanivel Rajan Shanmugavelayutham , Jitendra P. Singh
- Applicant: McAfee, Inc.
- Applicant Address: US TX Plano
- Assignee: McAfee, LLC
- Current Assignee: McAfee, LLC
- Current Assignee Address: US TX Plano
- Agency: Patent Capital Group
- Main IPC: G06F12/14
- IPC: G06F12/14 ; G06F21/56 ; G06F21/55 ; G06F21/53 ; G06F21/54 ; G06F21/57

Abstract:
In an example, there is provided a system and method for execution profiling detection of malicious software objects. An execution profiling (EXP) engine may be provided in conjunction with a binary translation engine (BTE). Both may operate within a trusted execution environment (TEE). Because many malware objects make assumptions about memory usage of host applications, they may cause exceptions when those assumptions prove untrue. The EXP engine may proactively detect such exceptions via the BTE when the BTE performs its translation function. Thus, malicious behavior may be detected before a binary runs on a system, and remedial measures may be provided.
Public/Granted literature
- US20160180090A1 EXECUTION PROFILING DETECTION OF MALICIOUS OBJECTS Public/Granted day:2016-06-23
Information query