Using memory management to detect and extract illegitimate code for malware analysis
Carsten Willems, Felix Freiling, Thorsten Holz · 2012
Exploits that successfully attack computers are typically based on some form of shellcode, i.e., illegitimate code that is injected by the attacker to take control of the system. Detecting and gathering such code is the first step to its detailed analysis. The amount and sophistication of modern malware calls for automated mechanisms that perform such detection and extraction.