Abstract
Methods, storage systems and computer program products implement embodiments of the present invention for protecting a computer by first deploying in a memory of the computer a hooked version of a syscall used by an operating system kernel of the computer. A notification of a call to the hooked version of the syscall from a user mode of the computer is received from the hooked version of the syscall, the notification including a return address in the memory and a set of features extracted from the call. The return address and the received features are analyzed so as to classify the call as benign or malicious, and an alert is generated for the computer upon classifying the new call as malicious.
Full Text
What is claimed is:
Methods, storage systems and computer program products implement embodiments of the present invention for protecting a computer by first deploying in a memory of the computer a hooked version of a syscall used by an operating system kernel of the computer. A notification of a call to the hooked version of the syscall from a user mode of the computer is received from the hooked version of the syscall, the notification including a return address in the memory and a set of features extracted from the call. The return address and the received features are analyzed so as to classify the call as benign or malicious, and an alert is generated for the computer upon classifying the new call as malicious.
Timeline
Filed
03/12/2026Published
07/16/2026Granted
Not AvailableIPC Codes(1)
G06F 21/56:Computer malware detection or handling, e.g. anti-virus arrangements