IP Library Granted Patent US 11,636,205
Granted Patent B2
US 11,636,205 · App. 17/205,230 · Granted Apr 25, 2023

Method and system for detecting malware using memory map

Inventor: Changseon Lee (Tokyo, JP)
Assignee: LINE CORPORATION
G06F21/566G06F21/554G06F21/564G06F21/568
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,636,205
App. No.
17/205,230
Granted
Apr 25, 2023
Kind
B2
Abstract

A malware detection method and system using a memory map. A malware detection method may include collecting, by processing circuitry, a plurality of memory maps from a plurality of client devices, a client program being installed in each of the plurality of client devices, analyzing, by the processing circuitry, a plurality of memory addresses of the plurality of memory maps to obtain an analysis result, and determining, by the processing circuitry, whether malware is present in one of the plurality of client devices based on the analysis result.

Claims (40)

1. A malware detection method performed by a computer apparatus including processing circuitry, the malware detection method comprising:

collecting, by the processing circuitry, a plurality of memory maps from a plurality of client devices, a client program being installed in each of the plurality of client devices;

counting, by the processing circuitry, a number of times each respective memory address among a plurality of memory addresses is in use in each of the plurality of memory maps, the plurality of memory addresses being included in each of the plurality of memory maps; and

determining, by the processing circuitry, whether malware is present in a first client device among the plurality of client devices based on a first number of times a first memory address among the plurality of memory addresses is in use among the plurality of memory maps.

2. The malware detection method of claim 1 , further comprising:

classifying the plurality of memory maps into one or more sets of memory maps for each of a plurality of client environments,

wherein the counting counts the number of times each respective memory address among the plurality of memory addresses is in use in each memory map among a first set of memory maps, the first set of memory maps being among the one or more sets of memory maps.

3. The malware detection method of claim 1 , wherein the determining comprises determining whether the first number of times is less than or equal to a second number of times.

4. The malware detection method of claim 3 , wherein the determining comprises determining that the malware is present in the first client device.

5. The malware detection method of claim 3 , wherein the second number of times is set based on a total number of the plurality of client devices and the number of times each respective memory address is in use in each of the plurality of memory maps.

6. The malware detection method of claim 1 , wherein the collecting comprises collecting the plurality of memory maps in response to the client program being executed in each of the plurality of client devices.

7. The malware detection method of claim 1 , wherein the plurality of memory addresses comprise at least a portion of memory addresses selected based on at least one of a status or a right of a corresponding memory address from among the plurality of memory addresses.

8. The malware detection method of claim 1 , further comprising:

restricting, by the processing circuitry, the first client device in response to determining the malware is present in the first client device.

9. A malware detection method performed by a computer apparatus comprising processing circuitry, the malware detection method comprising:

acquiring, by the processing circuitry, a memory map of the computer apparatus under control of a client program executed on the computer apparatus;

transmitting, by the processing circuitry, the memory map to a server that provides a service to the computer apparatus through the client program; and

receiving, by the processing circuitry, a signal from the server based on a first number of times a first memory address among a plurality of memory addresses is in use among a plurality of memory maps, the plurality of memory maps including the memory map and at least one other memory map of at least one other computer apparatus.

10. The malware detection method of claim 9 , further comprising:

transmitting, by the processing circuitry, information to the server, the information indicating a client environment in which the client program operates.

11. The malware detection method of claim 9 , wherein the server is configured to determine whether malware is present in one of a plurality of client devices based on a result of analyzing the plurality of memory addresses of the plurality of memory maps collected from the plurality of client devices, the plurality of client devices including the computer apparatus and the at least one other computer apparatus.

12. A non-transitory computer-readable record medium storing instructions that, when executed by at least one processor, cause the at least one processor to perform the malware detection method of claim 1 .

13. A computer apparatus comprising:

processing circuitry configured to cause the computer apparatus to,

collect a plurality of memory maps from a plurality of client devices, a client program being installed in each of the plurality of client devices,

count a number of times each respective memory address among a plurality of memory addresses is in use in each of the plurality of memory maps, the plurality of memory addresses being included in each of the plurality of memory maps, and

determine whether malware is present in a first client device among the plurality of client devices based on a first number of times a first memory address among the plurality of memory addresses is in use among the plurality of memory maps.

14. The computer apparatus of claim 13 , wherein the processing circuitry is configured to cause the computer apparatus to:

classify the plurality of memory maps into one or more sets of memory maps for each of a plurality of client environments;

count the number of times each respective memory address among the plurality of memory addresses is in use in each memory map among a first set of memory maps, the first set of memory maps being among the one or more sets of memory maps; and

determine whether malware is present in the first client device including determining whether the first number of times is less than or equal to a second number of times.

15. The computer apparatus of claim 14 , wherein the processing circuitry is configured to cause the computer apparatus to determine that the malware is present in the first client device.

16. The computer apparatus of claim 13 , wherein the processing circuitry is configured to cause the computer apparatus to restrict the first client device in response to determining the malware is present in the first client device.

17. The malware detection method of claim 8 , wherein the restricting comprises causing the first client device to reinstall the client program.

18. The malware detection method of claim 9 , further comprising:

restricting, by the processing circuitry, an operation of the client program in response to receiving the signal from the server.

19. The malware detection method of claim 18 , wherein the restricting comprises reinstalling the client program.

20. The computer apparatus of claim 16 , wherein the processing circuitry is configured to cause the computer apparatus to restrict the first client device by causing the first client device to reinstall the client program.

21. The malware detection method of claim 1 , wherein the determining comprises:

determining whether the first number of times is less than or equal to a second number of times, the second number of times being based on a total number of the plurality of client devices.

Assignments (7)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2024
From: Z INTERMEDIATE GLOBAL CORPORATION
To: LY CORPORATION
Reel/Frame 067096/0431 →
CHANGE OF NAME Recorded Apr 10, 2024
From: LINE CORPORATION
To: Z INTERMEDIATE GLOBAL CORPORATION
Reel/Frame 067069/0467 →
CORRECTIVE ASSIGNMENT TO CORRECT THE SPELLING OF THE ASSIGNEES CITY IN THE ADDRESS SHOULD BE TOKYO, JAPAN PREVIOUSLY RECORDED AT REEL: 058597 FRAME: 0303. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2023
From: A HOLDINGS CORPORATION
To: LINE CORPORATION
Reel/Frame 062401/0490 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE CITY SHOULD BE SPELLED AS TOKYO PREVIOUSLY RECORDED AT REEL: 058597 FRAME: 0141. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2023
From: LINE CORPORATION
To: A HOLDINGS CORPORATION
Reel/Frame 062401/0328 →
CHANGE OF NAME Recorded Dec 28, 2021
From: LINE CORPORATION
To: A HOLDINGS CORPORATION
Reel/Frame 058597/0141 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2021
From: A HOLDINGS CORPORATION
To: LINE CORPORATION
Reel/Frame 058597/0303 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 19, 2021
From: LEE, CHANGSEON
To: LINE CORPORATION
Reel/Frame 055644/0914 →
Priority Claims (1)
KR 10-2020-0034208 · Mar 20, 2020 · national
Continuity (1)
Related Publication 20210294895A1 · Sep 23, 2021