IP Library Granted Patent US 8,515,075
Granted Patent B1
US 8,515,075 · App. 12/322,220 · Granted Aug 20, 2013

Method of and system for malicious software detection using critical address space protection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,515,075
App. No.
12/322,220
Granted
Aug 20, 2013
Kind
B1
Abstract

A method of identifying malicious code based on identifying software executing out of writable memory of the computer system. In one embodiment, the identification of the malicious code occurs when the code accesses a predetermined memory address. This address can reside in the address space of an application, a library, or an operating system component. In one embodiment, the access to the predetermined address generates an exception invoking exception handling code. The exception handling code checks the memory attributes of the code that caused the exception and determines whether the code was running in writeable memory.

Claims (56)

1. A method comprising:

identifying particular code executing on a computer system and attempting to access a particular predetermined memory address of the computer system, wherein the predetermined memory address is associated with known access attempts by malicious code;

determining, based on identifying that the particular code attempts to access the particular predetermined memory address, that the particular code executes from writable memory space of the computer system while attempting to access the particular predetermined memory address;

identifying the particular code as malicious based, at least in part, on determination that the particular code attempts to access the particular predetermined memory address and executes from the writable memory space of the computer system, wherein an exception is to be generated that invokes an exception handler based at least in part on identifying the particular code as malicious;

generating an indicator to identify that the particular code was identified as malicious;

temporarily configuring the computer system to allow single stepping of the particular code following the exception; and

causing single stepping of the particular code.

2. The method of claim 1 , wherein the particular predetermined memory address is within a memory address space of data structures describing an application, a library, or an operating system component or their associated data.

3. The method of claim 2 , wherein the particular predetermined memory address is within the memory address space of a process environment block, an import table, an export table, a procedure linkage table, global offset table, program header, library header, or section header.

4. The method of claim 3 , further comprising terminating execution of a process, a thread, or an application associated with the particular code that caused the exception.

5. The method of claim 1 , wherein

determining that the particular code executes from writable memory space of the computer system is in response to identifying that the particular code accesses the particular predetermined memory address.

6. The method of claim 5 , wherein the computer system comprises configurable hardware adapted to control memory attributes of computer system memory and generate the exception upon access to a range of memory addresses that includes the particular predetermined memory address.

7. The method of claim 5 , further comprising terminating execution of a process, a thread, or an application associated with the particular code that caused the exception.

8. The method of claim 5 further comprising resuming execution of the particular code from a location at which the exception was generated.

9. The method of claim 8 , wherein temporarily configuring the computer system comprises:

configuring a processor associated with the computer processing system to execute the particular code at an instruction that caused the exception;

configuring an attribute of the particular predetermined memory address to a memory attribute that does not generate an exception when the processor executes the particular code that referenced the particular predetermined memory address;

configuring the attribute of the particular predetermined memory address the particular predetermined memory address attribute to an exception attribute; and

continuing processor execution at a next instruction following the particular code that referenced the particular predetermined memory address.

10. The method of claim 8 , wherein the particular predetermined memory address is not referenced by non-malicious code after initialization of the application, the library, or the operating system component.

11. A computer processing system comprising:

memory;

a processing component programmed to execute; and

an application, adapted when executed by the processing component to perform operations comprising:

identifying particular code executing on a computer system, wherein the particular code attempts to access a particular predetermined memory address of the computer system, wherein the particular predetermined memory address is associated with known access attempts by malicious code;

determining, based on identifying that the particular code attempts to access the particular predetermined memory address, that the particular code executes from writable memory space of the computer system while attempting to access the particular predetermined memory address; and

identifying the particular code as malicious based, at least in part, determination that the particular code attempts to access the particular predetermined memory address and executes from the writable memory space of the computer system, wherein an exception is to be generated that invokes an exception handler based at least in part on identifying the particular code as malicious;

generating an indicator to identify that the particular code was identified as malicious;

temporarily configuring the computer system to allow single stepping of the particular code following the exception; and

causing single stepping of the particular code.

12. The computer processing system of claim 11 , wherein the particular predetermined memory address is within an address space of data structures describing an application, a library, or an operating system component or their associated data.

13. The computer processing system of claim 12 , wherein the particular predetermined memory address is within the memory address space of a process environment block, an import table, an export table, a procedure linkage table, global offset table, program header, library header, or section header.

14. The computer processing system of claim 13 , wherein the application is adapted to perform further operations comprising terminating execution of a process, a thread, or an application associated with the code that caused the exception.

15. The computer processing system of claim 11 , wherein the application comprises:

the exception handler software invoked upon access to a memory address range including the particular predetermined memory address;

software to determine whether an attempted access was to the particular predetermined memory address;

and software to determine that code executes from writable memory.

16. The computer processing system of claim 15 , wherein the computer processing system further comprises configurable hardware for controlling memory attributes of computer system memory configurable to generate an exception upon access to a range of memory addresses that includes the particular predetermined memory address.

17. The computer processing system of claim 15 , further comprising terminating execution of a process, a thread, or an application associated with the particular code that caused the exception.

18. The computer processing system of claim 15 , wherein the application is further adapted to resume execution of the particular code from a location at which the exception was generated.

19. The computer processing system of claim 18 , wherein temporarily configuring the computer system comprises:

configuring a processor associated with the computer processing system to execute the particular code at an instruction that caused the exception;

configuring an attribute of the particular predetermined memory address to a memory attribute that does not generate an exception when the processor executes the particular code that referenced the particular predetermined memory address;

configuring the attribute of the particular predetermined memory address the particular predetermined memory address attribute to an exception attribute; and

continuing processor execution at a next instruction following the particular code that referenced the particular predetermined memory address.

20. An article comprising a non-transitory, machine-readable storage device storing instructions operable to cause at least one processor to perform operations comprising:

identifying particular code executing on a computer system and attempting to access a particular predetermined memory address of the computer system, wherein the predetermined memory address is associated with known access attempts by malicious code;

determining, based on identifying that the particular code attempts to access the particular predetermined memory address, that the particular code executes from writable memory space of the computer system while attempting to access the particular predetermined memory address;

identifying the particular code as malicious based, at least in part, on determination that the particular code attempts to access the particular predetermined memory address and executes from the writable memory space of the computer system, wherein an exception is to be generated that invokes an exception handler based at least in part on identifying the particular code as malicious;

generating an indicator to identify that the particular code was identified as malicious;

temporarily configuring the computer system to allow single stepping of the particular code following the exception; and

causing single stepping of the particular code.

21. The article of claim 20 , wherein the particular predetermined memory address is within an address space of data structures describing an application, a library, or an operating system component or their associated data.

22. The article of claim 20 , wherein identifying the particular code as malicious comprises:

generating an exception that invokes an exception handler when the particular code accesses the particular predetermined memory address, and wherein the exception handler determines if the particular code executes from writable memory.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
MERGER Recorded Jul 20, 2009
From: SOLIDCORE SYSTEMS, INC.
To: MCAFEE, INC.
Reel/Frame 022973/0458 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2009
From: SARAF, SUMAN; AGRAWAL, SHARAD; KUMAR, PANKAJ
To: SOLIDCORE SYSTEMS, INC.
Reel/Frame 022254/0260 →