Patent attributes
Systems and methods for malware detection and classification based on semantic analysis of memory dumps of malware are provided. According to one embodiment, a malware detector running within a computer system causes a sample file to be executed within a target process that is monitored by a process monitor of the malware detector. One or more memory dumps associated with the sample file are captured by the process monitor. A determination regarding whether the sample file represents malware is made by the malware detector by analyzing characteristics of at least one memory dump of the one or more memory dumps with reference to characteristics of memory dumps of a plurality of known malware samples.