US2022258955A1PendingUtilityA1

Non-disruptive mitigation of malware attacks

Assignee: DIGITAL IMMUNITY LLCPriority: Aug 28, 2018Filed: May 6, 2022Published: Aug 18, 2022
Est. expiryAug 28, 2038(~12.1 yrs left)· nominal 20-yr term from priority
G06F 21/566B65D 83/164G06F 12/1009G06F 21/561G06F 2212/657G06F 21/564G06F 21/53G06F 21/568G06F 12/109G06F 11/301G06F 2212/1052G06F 12/1441B65D 83/48B65D 83/42B65D 83/62B65D 83/546B65D 83/207B65D 83/525
63
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method and system for mitigating a malware attack are disclosed herein. A malware detection module iterates over a virtual memory address space associated with a process executing on a computer system. The malware detection module identifies a region of memory likely to be vulnerable to a malware attack. Responsive to identifying the region of memory, a thread hollowing module determines a specific process thread associated with the identified region of memory. The thread hollowing module renders the specific process thread inoperable.

Claims

exact text as granted — not AI-modified
What is claimed: 
     
         1 . A method of mitigating a malware attack, comprising:
 iterating, by a malware detection module, a virtual memory address space associated with a process executing on a computer system;   identifying, by the malware detection module, a region of memory likely to be vulnerable to a malware attack;   responsive to identifying the region of memory, determining, by a thread hollowing module, a specific process thread associated with the identified region of memory; and   rendering, by the thread hollowing module, the specific process thread inoperable.   
     
     
         2 . The method of  claim 1 , wherein the region of memory is associated with a second process thread. 
     
     
         3 . The method of  claim 2 , further comprising:
 allowing, by the thread hollowing module, the second process thread to continue to execute.   
     
     
         4 . The method of  claim 1 , wherein iterating, by the malware detection module, the virtual memory address space associated with the process executing on the computer system, comprises:
 iterating through each entry of the process' virtual memory lookup table; and   for each entry, analyzing a corresponding physical memory region.   
     
     
         5 . The method of  claim 1 , wherein identifying, by the malware detection module, the region of the memory likely to be vulnerable to the malware attack comprises:
 identifying patterns or attributes indicative of a malware attack or a vulnerability to a malware attack.   
     
     
         6 . The method of  claim 1 , wherein rendering, by the thread hollowing module, the specific process thread inoperable comprises:
 overwriting the identified region of memory with a series of no-ops.   
     
     
         7 . The method of  claim 1 , wherein rendering, by the thread hollowing module, the specific process thread inoperable comprises:
 injecting a return operation or a control operation into a stack frame associated with the specific process thread.   
     
     
         8 . A system, comprising:
 a processor; and   a memory having programming instructions stored thereon, which, when executed by the processor, performs one or more operations comprising:
 iterating, by a malware detection module, a virtual memory address space associated with a process executing on a computer system; 
 identifying, by the malware detection module, a region of memory likely to be vulnerable to a malware attack; 
 responsive to identifying the region of memory, determining, by a thread hollowing module, a specific process thread associated with the identified region of memory; and 
 rendering, by the thread hollowing module, the specific process thread inoperable. 
   
     
     
         9 . The system of  claim 8 , wherein the region of memory is associated with a second process thread. 
     
     
         10 . The system of  claim 9 , wherein the operations further comprising:
 allowing, by the thread hollowing module, the second process thread to continue to execute.   
     
     
         11 . The system of  claim 8 , wherein iterating, by the malware detection module, the virtual memory address space associated with the process executing on the computer system, comprises:
 iterating through each entry of the process' virtual memory lookup table; and   for each entry, analyzing a corresponding physical memory region.   
     
     
         12 . The system of  claim 8 , wherein identifying, by the malware detection module, the region of the memory likely to be vulnerable to the malware attack comprises:
 identifying patterns or attributes indicative of a malware attack or a vulnerability to a malware attack.   
     
     
         13 . The system of  claim 8 , wherein rendering, by the thread hollowing module, the specific process thread inoperable comprises:
 overwriting the identified region of memory with a series of no-ops.   
     
     
         14 . The system of  claim 8 , wherein rendering, by the thread hollowing module, the specific process thread inoperable comprises:
 injecting a return operation or a control operation into a stack frame associated with the specific process thread.   
     
     
         15 . A non-transitory computer readable medium having instructions stored thereon, which, when executed by a processor, cause the processor to perform an operation, comprising:
 iterating, by a malware detection module, a virtual memory address space associated with a process executing on a computer system;   identifying, by the malware detection module, a region of memory likely to be vulnerable to a malware attack;   responsive to identifying the region of memory, determining, by a thread hollowing module, a specific process thread associated with the identified region of memory; and   rendering, by the thread hollowing module, the specific process thread inoperable.   
     
     
         16 . The non-transitory computer readable medium of  claim 15 , wherein the region of memory is associated with a second process thread. 
     
     
         17 . The non-transitory computer readable medium of  claim 16 , further comprising:
 allowing, by the thread hollowing module, the second process thread to continue to execute.   
     
     
         18 . The non-transitory computer readable medium of  claim 15 , wherein iterating, by the malware detection module, the virtual memory address space associated with the process executing on the computer system, comprises:
 iterating through each entry of the process' virtual memory lookup table; and   for each entry, analyzing a corresponding physical memory region.   
     
     
         19 . The non-transitory computer readable medium of  claim 15 , wherein identifying, by the malware detection module, the region of the memory likely to be vulnerable to the malware attack comprises:
 identifying patterns or attributes indicative of a malware attack or a vulnerability to a malware attack.   
     
     
         20 . The non-transitory computer readable medium of  claim 15 , wherein rendering, by the thread hollowing module, the specific process thread inoperable comprises:
 overwriting the identified region of memory with a series of no-ops.

Join the waitlist — get patent alerts

Track US2022258955A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.