Fortinet, Inc.
Malware detection and classification based on memory semantic analysis

Last updated:

Abstract:

Systems and methods for malware detection and classification based on semantic analysis of memory dumps of malware are provided. According to one embodiment, a malware detector running within a computer system causes a sample file to be executed within a target process that is monitored by a process monitor of the malware detector. One or more memory dumps associated with the sample file are captured by the process monitor. A determination regarding whether the sample file represents malware is made by the malware detector by analyzing characteristics of at least one memory dump of the one or more memory dumps with reference to characteristics of memory dumps of a plurality of known malware samples.

Status:
Grant
Type:

Utility

Filling date:

26 Oct 2016

Issue date:

17 Sep 2019