Invention Grant
- Patent Title: Methods for protecting software hooks, and related computer security systems and apparatus
-
Application No.: US16144444Application Date: 2018-09-27
-
Publication No.: US11042633B2Publication Date: 2021-06-22
- Inventor: Paul M. Drapeau , Brian M. Sturk
- Applicant: Carbon Black, Inc.
- Applicant Address: US MA Waltham
- Assignee: Carbon Black, Inc.
- Current Assignee: Carbon Black, Inc.
- Current Assignee Address: US MA Waltham
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F21/54 ; G06F21/55 ; G06F9/30 ; G06F9/54 ; G06K9/62 ; G06F11/30 ; G06F21/56 ; G06F9/455

Abstract:
A computing apparatus for protecting software hooks from interference may include a processing device and a memory access monitoring device configured to monitor access to the memory addresses of one or more hooks. When a task T1 attempts to write to a memory address of a monitored hook, the monitoring device may generate a notification (e.g., an interrupt), and the processing device may pause execution of the task T1 and initiate execution of a hook protection task T2. The hook protection task T2 may determine whether to allow task T1 to modify the monitored hook. If task T1 is not a trusted task (e.g., if task T1 is or may be malware), the processing device blocks T1 from modifying the monitored hook. In this manner, some attempts to unhook critical software hooks may be thwarted.
Public/Granted literature
- US20190095616A1 METHODS FOR PROTECTING SOFTWARE HOOKS, AND RELATED COMPUTER SECURITY SYSTEMS AND APPARATUS Public/Granted day:2019-03-28
Information query