Is a
Patent attributes
Patent Jurisdiction
Patent Number
Patent Inventor Names
Mark Kennedy0
Shane Pereira0
Date of Patent
June 26, 2012
0Patent Application Number
121637470
Date Filed
June 27, 2008
0Patent Citations Received
Patent Primary Examiner
Patent abstract
A method includes creating an intercept function for a tracked DLL function of a DLL being loaded into a suspicious module. Upon a determination that the tracked DLL function is invoked, a determination is made as to whether a return address of a caller of the tracked DLL function is within a legitimate return address range. The legitimate return address range includes an address range of the intercept function and excludes an address range of the suspicious module. If the return address is within the suspicious module, the suspicious module called the tracked DLL function directly. This indicates that the suspicious module is malicious and so protective action is taken.
Timeline
No Timeline data yet.
Further Resources
No Further Resources data yet.