Invention Grant
- Patent Title: Detecting buffer overflows using frame pointer characteristics
- Patent Title (中): 使用帧指针特性检测缓冲区溢出
-
Application No.: US11095276Application Date: 2005-03-30
-
Publication No.: US08037526B1Publication Date: 2011-10-11
- Inventor: Sourabh Satish , Matthew Conover
- Applicant: Sourabh Satish , Matthew Conover
- Applicant Address: US CA Mountain View
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Mountain View
- Agency: Gunnison, McKay & Hodgson, L.L.P.
- Agent Philip McKay
- Main IPC: G06F12/14
- IPC: G06F12/14

Abstract:
A method makes use of positional relationships in a memory stack between the frame pointer, such as the Extended Base Pointer (EBP) in Windows®-based systems, of a critical call initiating function making a call to a critical operating system (OS) function, the top of stack position, such as the Process Environment Block (PEB) in Windows® based systems, and the bottom of stack position, such as the Extended Stack pointer (ESP) in a Windows® based system, to detect and block buffer overflows.
Information query