The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jan. 05, 2021

Filed:

Jul. 23, 2018
Applicant:

Fireeye, Inc., Milpitas, CA (US);

Inventors:

Sushant Paithane, Sunnyvale, CA (US);

Sai Omkar Vashisht, Morgan Hill, CA (US);

Assignee:

FireEye, Inc., Milpitas, CA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 21/56 (2013.01); H04L 29/06 (2006.01); G06F 21/55 (2013.01); G06F 21/53 (2013.01);
U.S. Cl.
CPC ...
H04L 63/1416 (2013.01); G06F 21/554 (2013.01); G06F 21/566 (2013.01); H04L 63/1425 (2013.01); H04L 63/1466 (2013.01); G06F 21/53 (2013.01);
Abstract

For one embodiment, a computerized method for detecting exploit attacks on an interpreter comprises configuring a virtual machine including a user mode and a kernel mode and processing an object by an application operating in the user mode of the virtual machine. Responsive to the processing of the object, detecting a loading of an interpreter. Furthermore, responsive to the loading of the interpreter, inserting one or more intercept points for detecting one or more types of software calls from the interpreter or for detecting a certain type or certain types of activities occurring within the interpreter. Thereafter, an exploit attack is detected as being conducted by the object in response to the interpreter invoking a software call that corresponds to the one or more types of software calls that is considered anomalous when invoked by the interpreter or an anomalous activity being conducted within the interpreter.


Find Patent Forward Citations

Loading…