Abstract
A method for detecting an attempt to side-load a malicious Dynamic Link Library (DLL) includes identifying a load image event in a computer system, the load image event indicating that an operating system has loaded an application together with a DLL. An event filtering criterion that assesses signatures of the application and the DLL is applied to the load image event. A profile filtering criterion that assesses prevalence of characteristics of the DLL within the computer system is applied to the load image event. Responsively to meeting both the event filtering criterion and the profile filtering criterion, a determination is made that the load image event is suspected of indicating a DLL side-loading attack.
Full Text
What is claimed is:
A method for detecting an attempt to side-load a malicious Dynamic Link Library (DLL) includes identifying a load image event in a computer system, the load image event indicating that an operating system has loaded an application together with a DLL. An event filtering criterion that assesses signatures of the application and the DLL is applied to the load image event. A profile filtering criterion that assesses prevalence of characteristics of the DLL within the computer system is applied to the load image event. Responsively to meeting both the event filtering criterion and the profile filtering criterion, a determination is made that the load image event is suspected of indicating a DLL side-loading attack.
Timeline
Filed
04/27/2026Published
09/03/2026Granted
Not AvailableIPC Codes(1)
G06F 21/56:Computer malware detection or handling, e.g. anti-virus arrangements