INFERENTIAL EXPLOIT ATTEMPT DETECTION
A security agent implemented on a monitored computing device is described herein. The security agent is configured to detect an action of interest (AoI) that may be probative of a security exploit and to determine a context in which that AoI occurred. Based on that context, the security agent is further configured to decide whether the AoI is a security exploit and can take preventative action to prevent the exploit from being completed.
1 . A method comprising:
receiving, by a call stack actor (CSA), a request to examine a context of an action of interest (AoI);
generating, by the CSA and based at least in part on the request, a characterization of a call stack associated with the AoI, the generating based at least in part on walking through the call stack; and
determining, by a security agent and based at least in part on the characterization, that the AoI includes a security exploit.