Patent 11880453 was granted and assigned to Sophos on January, 2024 by the United States Patent and Trademark Office.
A compute instance is instrumented to detect certain kernel memory allocation functions, in particular functions that allocate heap memory and/or make allocated memory executable. Dynamic shell code exploits can then be detected when code executing from heap memory allocates additional heap memory and makes that additional heap memory executable.