US2022258955A1PendingUtilityA1
Non-disruptive mitigation of malware attacks
Est. expiryAug 28, 2038(~12.1 yrs left)· nominal 20-yr term from priority
Inventors:Henry R. Tumblin
G06F 21/566B65D 83/164G06F 12/1009G06F 21/561G06F 2212/657G06F 21/564G06F 21/53G06F 21/568G06F 12/109G06F 11/301G06F 2212/1052G06F 12/1441B65D 83/48B65D 83/42B65D 83/62B65D 83/546B65D 83/207B65D 83/525
63
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A method and system for mitigating a malware attack are disclosed herein. A malware detection module iterates over a virtual memory address space associated with a process executing on a computer system. The malware detection module identifies a region of memory likely to be vulnerable to a malware attack. Responsive to identifying the region of memory, a thread hollowing module determines a specific process thread associated with the identified region of memory. The thread hollowing module renders the specific process thread inoperable.
Claims
exact text as granted — not AI-modifiedWhat is claimed:
1 . A method of mitigating a malware attack, comprising:
iterating, by a malware detection module, a virtual memory address space associated with a process executing on a computer system; identifying, by the malware detection module, a region of memory likely to be vulnerable to a malware attack; responsive to identifying the region of memory, determining, by a thread hollowing module, a specific process thread associated with the identified region of memory; and rendering, by the thread hollowing module, the specific process thread inoperable.
2 . The method of claim 1 , wherein the region of memory is associated with a second process thread.
3 . The method of claim 2 , further comprising:
allowing, by the thread hollowing module, the second process thread to continue to execute.
4 . The method of claim 1 , wherein iterating, by the malware detection module, the virtual memory address space associated with the process executing on the computer system, comprises:
iterating through each entry of the process' virtual memory lookup table; and for each entry, analyzing a corresponding physical memory region.
5 . The method of claim 1 , wherein identifying, by the malware detection module, the region of the memory likely to be vulnerable to the malware attack comprises:
identifying patterns or attributes indicative of a malware attack or a vulnerability to a malware attack.
6 . The method of claim 1 , wherein rendering, by the thread hollowing module, the specific process thread inoperable comprises:
overwriting the identified region of memory with a series of no-ops.
7 . The method of claim 1 , wherein rendering, by the thread hollowing module, the specific process thread inoperable comprises:
injecting a return operation or a control operation into a stack frame associated with the specific process thread.
8 . A system, comprising:
a processor; and a memory having programming instructions stored thereon, which, when executed by the processor, performs one or more operations comprising:
iterating, by a malware detection module, a virtual memory address space associated with a process executing on a computer system;
identifying, by the malware detection module, a region of memory likely to be vulnerable to a malware attack;
responsive to identifying the region of memory, determining, by a thread hollowing module, a specific process thread associated with the identified region of memory; and
rendering, by the thread hollowing module, the specific process thread inoperable.
9 . The system of claim 8 , wherein the region of memory is associated with a second process thread.
10 . The system of claim 9 , wherein the operations further comprising:
allowing, by the thread hollowing module, the second process thread to continue to execute.
11 . The system of claim 8 , wherein iterating, by the malware detection module, the virtual memory address space associated with the process executing on the computer system, comprises:
iterating through each entry of the process' virtual memory lookup table; and for each entry, analyzing a corresponding physical memory region.
12 . The system of claim 8 , wherein identifying, by the malware detection module, the region of the memory likely to be vulnerable to the malware attack comprises:
identifying patterns or attributes indicative of a malware attack or a vulnerability to a malware attack.
13 . The system of claim 8 , wherein rendering, by the thread hollowing module, the specific process thread inoperable comprises:
overwriting the identified region of memory with a series of no-ops.
14 . The system of claim 8 , wherein rendering, by the thread hollowing module, the specific process thread inoperable comprises:
injecting a return operation or a control operation into a stack frame associated with the specific process thread.
15 . A non-transitory computer readable medium having instructions stored thereon, which, when executed by a processor, cause the processor to perform an operation, comprising:
iterating, by a malware detection module, a virtual memory address space associated with a process executing on a computer system; identifying, by the malware detection module, a region of memory likely to be vulnerable to a malware attack; responsive to identifying the region of memory, determining, by a thread hollowing module, a specific process thread associated with the identified region of memory; and rendering, by the thread hollowing module, the specific process thread inoperable.
16 . The non-transitory computer readable medium of claim 15 , wherein the region of memory is associated with a second process thread.
17 . The non-transitory computer readable medium of claim 16 , further comprising:
allowing, by the thread hollowing module, the second process thread to continue to execute.
18 . The non-transitory computer readable medium of claim 15 , wherein iterating, by the malware detection module, the virtual memory address space associated with the process executing on the computer system, comprises:
iterating through each entry of the process' virtual memory lookup table; and for each entry, analyzing a corresponding physical memory region.
19 . The non-transitory computer readable medium of claim 15 , wherein identifying, by the malware detection module, the region of the memory likely to be vulnerable to the malware attack comprises:
identifying patterns or attributes indicative of a malware attack or a vulnerability to a malware attack.
20 . The non-transitory computer readable medium of claim 15 , wherein rendering, by the thread hollowing module, the specific process thread inoperable comprises:
overwriting the identified region of memory with a series of no-ops.Join the waitlist — get patent alerts
Track US2022258955A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.