Profiling event based exploit detection
US9984230B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Jun 26, 2015 |
| Grant date | May 29, 2018 |
| Priority date | — |
| Expiry date | Dec 22, 2035 |
Classification
- Technology area (CPC G)Physics
- CPC primaryG06F21/554
- WIPO fieldComputer technology
- WIPO sectorElectrical engineering
Abstract
Particular embodiments described herein provide for an electronic device that can be configured to execute an application in a system with an operating system, perform event tracing for the application, analyze each instruction pointer from the event tracing, and determine if an instruction pointer points to an orphan page of memory. The orphan page can be a region of code that is not associated with the application, a region of code that is unidentified, or unusual code that is not associated with the application. In addition, the event tracing can be an embedded application that is part of the operating system.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.