IL288122A

Systems and methods for executable code detection, automatic feature extraction and position independent code detection

Abstract

This record has no abstract on file.

IL288122A, drawing sheet 1
Sheet 1 of 20

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

24 claims: 17 independent, 7 dependent

  1. 1
    WHAT IS CLAIMED IS:1. A system for library position independent code detection, the system comprising: one or more computer readable storage devices configured to store a plurality of computer executable instructions;and one or more hardware computer processors in communication with the one or more computer readable storage devices and configured to execute the plurality of computer executable instructions in order to cause the system to: instrument an import address table (IAT) entry of a monitored symbol, the instrumenting of the IAT entry comprising: replacing a monitored symbol address within the IAT entry of the monitored symbol with a modified address;executing a trampoline code upon a call of the modified address to detect and validate a call of the monitored symbol;and redirecting the call of the modified address to the monitored symbol address;instrument one or more Loader API functions, the instrumenting of the one or more Loader API functions comprising: modifying the one or more Loader API functions to return values that lead to the trampoline code;detouring execution of the monitored symbol to a detour code to detect and validate a call of the monitored symbol;and redirecting the call of the monitored symbol to the monitored symbol address;monitor the trampoline code and the detour code of the monitored symbol to determine if calls from an executable comprises a static call, a dynamic call, or a local call;and if the system determines that at least one call from the executable does not comprise a static call, dynamic call, or a local call, flag the executable as suspicious or malicious for a malware detection system.
  2. 2
    The system of Claim 1, wherein the system is further caused to, if the system determines that the at least one call does not comprise a static call, dynamic call, or local call, classify the at least one call as an independent call.
  3. 3
    The system of Claim 1, wherein the system is further caused to, if the system determines that the calls comprise a static call, dynamic call, or local call, classify the calls as benign calls.
  4. 4
    The system of Claim 1 or 2, wherein the system is further caused to, if the system determines that the calls comprise a static call, dynamic call, or local call, classify the executable as benign.
  5. 5
    The system of Claim 1, further comprising:A hooking engine comprising the trampoline code and the detour code;and one or more call databases configured to store data related to the calls.
  6. 6
    The system of Claim any one of Claims 1-5, wherein the dynamic call comprises an attempted retrieval of the monitored symbol address during execution of the executable.
  7. 7
    The system of any one of Claims 1-6, wherein the static call comprises an attempted retrieval of the monitored symbol address during initialization of the executable.
  8. 8
    The system of any one of Claims 1-7, wherein determination of whether the calls from the executable comprise a local call comprises monitoring the detour Code to determine if a return address is located in the same executable as the monitored symbol.
  9. 9
    The system any one of Claims 1-8, wherein the one or more Loader API functions comprise one or both of GetModuleHandle or GetProcAddress.
  10. 10
    The system of any one of Claims 1-9, wherein the at least one call is initiated by the executable using metadata retrieved from a module comprising the monitored symbol
  11. 11
    The system of Claim any one of Claims 1-9, wherein the at least one call is initiated by the executable using data retried from a Loader internal record.
  12. 12
    The system of any one of Claims 1-9, wherein the at least one call is initiated by the executable by calling the monitored symbol without triggering the trampoline code.
  13. 13
    A computer implemented method for library position independent code detection, the method comprising:instrumenting, by a computer system, an import address table (IAT) entry of a monitored symbol, the instrumenting of the IAT entry comprising: replacing a monitored symbol address within the IAT entry of the monitored symbol with a modified address;executing a trampoline code upon a call of the modified address to detect and validate a static call of the monitored symbol;and redirecting the call of the modified address to the monitored symbol address;instrumenting, by the computer system, one or more Loader API functions, the instrumenting of the one or more Loader API functions comprising: modifying the one or more Loader API functions to return values that lead to the trampoline code;detouring the execution of the monitored symbol to a detour code to detect and validate a call of the monitored symbol;and redirecting the call of the monitored symbol to the monitored symbol address;monitoring, by the computer system, the trampoline code and the detour code of the monitored symbol to determine if calls from an executable comprise a static call, a dynamic call, or a local call;and if the computer system determines that at least one call from the executable does not comprise a static call, dynamic call, or a local call, flagging, by the computer system, the executable as suspicious or malicious for a malware detection system, wherein the computer system comprises a computer processor and an electronic storage medium.
  14. 14
    The method of Claim 13, further comprising, if the computer system determines that the at least one call does not comprise a static call, dynamic call, or local call, classifying the at least one call as an independent call.
  15. 15
    The method of Claim 13, further comprising, if the computer system determines that the calls comprise a static call, dynamic call, or local call, classifying the calls as benign calls.
  16. 16
    The method of Claim 13 or 14, further comprising, if the computer system determines that the calls comprise a static call, dynamic call, or local call, classifying the executable as benign.
  17. 17
    The method of any one of Claims 13-16, wherein the trampoline code and the detour code comprise one or more portions of a hooking engine, the hooking engine connected to a call database configured to store data related to the calls.
  18. 18
    The method of any one of Claims 13-17, wherein the dynamic call comprises an attempted retrieval of the monitored symbol address during execution of the executable.
  19. 19
    The method of Claim any one of Claims 13-18, wherein the static call comprises an attempted retrieval of the monitored symbol address during initialization of the executable.
  20. 20
    The method of any one of Claims 13-19, wherein determination of whether the calls from the executable comprise a local call comprises monitoring the detour Code to determine if a return address is located in the same executable as the monitored symbol.
  21. 21
    The method of any one of Claims 13-20, wherein the one or more Loader API functions comprise one or both of GetModuleHandle or GetProcAddress.
  22. 22
    The method of Claim any one of Claims 13-21, wherein the at least one call is initiated by the executable using metadata retrieved from a module comprising the monitored symbol
  23. 23
    The method of any one of Claims 13-21, wherein the at least one call is initiated by the executable using data retried from a Loader internal record.
  24. 24
    The method of any one of Claims 13-21, wherein the at least one call is initiated by the executable by calling the monitored symbol without triggering the trampoline code.
Independent claims24