/Detection Of Dynamic Link Library (dll) Side Loading Attacks
Abstract

A method for detecting an attempt to side-load a malicious Dynamic Link Library (DLL) includes identifying a load image event in a computer system, the load image event indicating that an operating system has loaded an application together with a DLL. An event filtering criterion that assesses signatures of the application and the DLL is applied to the load image event. A profile filtering criterion that assesses prevalence of characteristics of the DLL within the computer system is applied to the load image event. Responsively to meeting both the event filtering criterion and the profile filtering criterion, a determination is made that the load image event is suspected of indicating a DLL side-loading attack.

Full Text

What is claimed is:

A method for detecting an attempt to side-load a malicious Dynamic Link Library (DLL) includes identifying a load image event in a computer system, the load image event indicating that an operating system has loaded an application together with a DLL. An event filtering criterion that assesses signatures of the application and the DLL is applied to the load image event. A profile filtering criterion that assesses prevalence of characteristics of the DLL within the computer system is applied to the load image event. Responsively to meeting both the event filtering criterion and the profile filtering criterion, a determination is made that the load image event is suspected of indicating a DLL side-loading attack.
Timeline
Filed
04/27/2026
Published
09/03/2026
Granted
Not Available
IPC Codes(1)
G06F 21/56:Computer malware detection or handling, e.g. anti-virus arrangements