Patent
Method to detect application execution hijacking using memory protection
Amit Malik,Reghav Pande,Aakash Jain +2 more
- 30 Sep 2015
74
TL;DR: In this paper, a system comprising a dynamic analysis server comprising one or more virtual machines is disclosed, wherein the virtual machines may be configured to execute certain event logic with respect to a loaded module.
read more
Abstract: According to one embodiment, a system comprising a dynamic analysis server comprising one or more virtual machines is disclosed, wherein the one or more virtual machines may be configured to execute certain event logic with respect to a loaded module. The virtual machines may be communicatively coupled to a virtual machine manager and a database; and rule-matching logic comprising detection logic, wherein the detection logic is configured to determine (1) whether an access source is attempting to access a protected region such as a page guarded area; and (2) determine whether the access source is from the heap. The system further comprises reporting logic that is configured to generate an alert so as to notify a user and/or network administrator of a probable application-execution hijacking attack.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
Patent
Cyber attack early warning system
Divyesh Mehra,Abhishek Singh +1 more
- 30 Sep 2015
TL;DR: In this article, a system and method for generating an alert regarding a potential attack is described, which involves receiving data associated with previously analyzed or known malware attacks by a first network device, and also receiving an attack alert associated with an object analyzed and identified as suspicious by a second network device.
79
Patent
System and method for detecting interpreter-based exploit attacks
Sushant Paithane,Sai Vashisht +1 more
- 29 Sep 2015
TL;DR: In this article, a computerized method for detecting exploit attacks on an interpreter comprises configuring a virtual machine including a user mode and a kernel mode and processing an object by an application operating in the user mode of the virtual machine.
74
Patent
System and method for triggering analysis of an object for malware in response to modification of that object
Vineet Kumar,Alexander Otvagin,Nikita Borodulin +2 more
- 30 Dec 2015
TL;DR: In this paper, a system featuring one or more processors and memory that includes monitoring logic is described, which is configured to monitor for and detect a notification message that is directed to a destination other than the monitoring logic and identify an event associated with a change in state of a data store associated with the file system.
70
Patent
Analytics-based security monitoring system and method
Justin Neumann
- 13 Apr 2015
TL;DR: In this paper, an analytics-based security monitoring system adapted to detect a plurality of behavioral characteristics from behavioral data, each representing an action conducted in a computing environment, is presented.
59
Patent
Attribute-controlled malware detection
Mumtaz Siddiqui,Manju Radhakrishnan,Deepak Agarwal +2 more
- 29 Mar 2018
TL;DR: In this article, the authors proposed a method for authenticating access to a subscription-based service to detect an attempted cyber-attack using service policy level information and information based on operational metadata, which includes metadata that pertains to an operating state of one or more clusters of a plurality of clusters of the subscription based service.
37
References
•Proceedings Article
Dynamic Taint Analysis for Automatic Detection, Analysis, and Signature Generation of Exploits on Commodity Software
James Newsome,Dawn Song +1 more
- 01 Jan 2005
TL;DR: TaintCheck as mentioned in this paper performs dynamic taint analysis by performing binary rewriting at run time, which can reliably detect most types of exploits and produces no false positives for any of the many different programs that were tested.
ReVirt: enabling intrusion analysis through virtual-machine logging and replay
George W. Dunlap,Samuel T. King,Sukru Cinar,Murtaza A. Basrai,Peter M. Chen +4 more
- 09 Dec 2002
TL;DR: ReVirt removes the dependency on the target operating system by moving it into a virtual machine and logging below the virtual machine, and enables it to provide arbitrarily detailed observations about what transpired on the system, even in the presence of non-deterministic attacks and executions.
Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detection
Thomas Henry Ptacek,Timothy Nakula Newsham +1 more
- 01 Jan 1998
TL;DR: Three classes of attacks which exploit fundamentally problems with the reliability of passive protocol analysis are defined--insertion, evasion and denial of service attacks--and how to apply these three types of attacks to IP and TCP protocol analysis is described.
•Proceedings Article
Autograph: toward automated, distributed worm signature detection
TL;DR: Autograph as mentioned in this paper is a system that automatically generates signatures for novel Internet worms that propagate using TCP transport, and it is designed to produce signatures that exhibit high sensitivity (high true positives) and high specificity (low false positives).
•Proceedings Article
DroidScope: seamlessly reconstructing the OS and Dalvik semantic views for dynamic Android malware analysis
Lok Kwong Yan,Heng Yin +1 more
- 08 Aug 2012
TL;DR: DroidScope is presented, an Android analysis platform that continues the tradition of virtualization-based malware analysis and reconstructs both the OS-level and Java-level semantics simultaneously and seamlessly.
Related Papers (5)
Yung-Chang Liang,Said Kaki,Yi-Fen Chen +2 more
- 02 Mar 2006
Amit Dang,Preet Mohinder +1 more
- 21 Aug 2009
Vyacheslav E. Rusakov,Alexander V. Shiryaev +1 more
- 30 Jun 2011