Anti-malware program with stalling code detection
US9817974B1 · kind B1 · utility
9Cited by
5References
13Claims
0Family size
Assignee
Inventors
Key dates
| Filing date | Nov 10, 2015 |
| Grant date | Nov 14, 2017 |
| Priority date | — |
| Expiry date | Nov 10, 2035 |
Classification
- Technology area (CPC G)Physics
- CPC primaryG06F21/566
- WIPO fieldComputer technology
- WIPO sectorElectrical engineering
Abstract
Execution of a sample program being evaluated for malware is initiated and then suspended to set breakpoints on timing operations of the sample program. Execution of the sample program is suspended again when a breakpoint is hit, at which time a loop is identified in the sample program and evaluated for presence of stalling code. Execution flow of the sample program is changed to exit the loop when the loop is determined to include the stalling code.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.