Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

6 results about "Memory analysis" patented technology

Memory detection method and system for virtual machine

The application discloses a memory detection method and system of a virtual machine. The method is applied to a memory detection system, and the memory detection system is used for running a main process to execute the following method: in response to an inter-process communication request of at least one detection process, determining to-be-detected memory of a virtual machine; performing memory analysis on the to-be-detected memory according to a detection item, and obtaining an analysis result, wherein the analysis result comprises memory information of the to-be-detected memory under an operating system where the virtual machine is located; transmitting the analysis result to the detection process through inter-process communication between the main process and the detection process, wherein the analysis result is used for detection according to the detection item in the detection process, and a memory detection result is obtained; and obtaining the memory detection result corresponding to the analysis result through inter-process communication. The application solves the technical problem that the stability of a detection system for detecting memory of a virtual machine by relying on proxy software is poor.
Owner:ALIBABA CLOUD COMPUTING CO LTD

Just in time memory analysis for malware detection

ActiveUS12639438B2Platform integrity maintainanceData packMemory profiling
Methods and apparatus consistent with the present disclosure may use instrumentation code that remains transparent to an application program that the instrumentation code has been injected into. In certain instances, data sets that include executable code may be received via packetized communications or be received via other means, such as, receiving a file from a data store. The present technique allows a processor executing instrumentation code to monitor actions performed by the program code included in a received data set. Malware may be detected by scanning suspect program code with a malware scanner, malware may be detected by identifying suspicious actions performed by a set of program code, or malware may be detected by a combination of such techniques.
Owner:SONICWALL INC

Heap memory analysis method and device, computer device, chip and chip module

The application relates to a heap memory analysis method and device, computer equipment, a chip and a chip module. The method comprises the following steps: in response to a heap memory processing instruction for a to-be-analyzed heap memory, determining the array identifier of a preset array corresponding to the to-be-analyzed heap memory according to the heap memory address corresponding to the heap memory processing instruction; updating the array information of the preset array according to the heap memory processing instruction and the array identifier, to obtain the updated array information of the preset array; and generating a memory analysis report corresponding to the to-be-analyzed heap memory based on the updated array information. The method can improve the analysis efficiency of the heap memory.
Owner:RDA MICROELECTRONICS TECH (TIANJIN) CO LTD

Just in time memory analysis for malware detection

PendingUS20260203405A1Data packMemory profiling
Methods and apparatus consistent with the present disclosure may use instrumentation code that remains transparent to an application program that the instrumentation code has been injected into. In certain instances, data sets that include executable code may be received via packetized communications or be received via other means, such as, receiving a file from a data store. The present technique allows a processor executing instrumentation code to monitor actions performed by the program code included in a received data set. Malware may be detected by scanning suspect program code with a malware scanner, malware may be detected by identifying suspicious actions performed by a set of program code, or malware may be detected by a combination of such techniques.
Owner:SONICWALL INC

A vulnerability exploitation agent system, method and apparatus based on steering engineering

PendingCN122365521AMemory profilingTerm memory
This invention discloses a vulnerability exploitation agent system, method, and apparatus based on the driving engineering framework, relating to the field of artificial intelligence, to address the vulnerability problem in the autonomous execution of long-chain tasks by vulnerability exploitation agents. It constructs a vulnerability exploitation agent system comprising an environment perception and object representation layer, an execution layer, an orchestration layer, a memory layer, a semantic management layer, and a security layer. Based on the logic of global constraint pre-positioning – progressive information disclosure – full-link behavior control – autonomous closed-loop execution – standardized output of results, it leverages the core mechanisms of the driving engineering framework, such as event-driven interception and verification bus, dynamic loading of prompts, memory compression, autonomous task execution loop, and tool permission gating, to form a fully traceable vulnerability exploitation scheme. This application can solve the problems of difficult binary semantic analysis and memory analysis in long-chain vulnerability exploitation tasks, improving task execution efficiency and accuracy.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

A Software Component Verification Method Based on Runtime Memory Analysis

PendingCN122309327ADigital dataTerm memory
This invention relates to the field of electronic digital data processing technology and discloses a software component verification method based on runtime memory analysis. The method includes: reading a virtual reference address and the instruction stream to be verified when the target memory page attribute switches from non-executable to executable; dividing the instruction stream to be verified into continuous memory blocks according to the hardware cache line alignment length; counting the number of instruction start boundaries within each memory block and serializing them in ascending address order to generate a feature vector representing load density; matching the feature vector with a reference library and sending an interception signal to the kernel scheduler when the distance metric exceeds a threshold. This invention utilizes the physical boundaries of the hardware cache lines to capture load structure distortions caused by code obfuscation, avoiding complex semantic parsing logic, effectively reducing system latency caused by verification, and synergistically improving the verification confidence for dynamically mutated components.
Owner:GUIZHOU DONGGUAN TECH