Invention Grant
- Patent Title: Control flow redirection and analysis for detecting vulnerability exploitation
- Patent Title (中): 用于检测漏洞利用的控制流重定向和分析
-
Application No.: US11766048Application Date: 2007-06-20
-
Publication No.: US08296848B1Publication Date: 2012-10-23
- Inventor: Kent E. Griffin , Carey S. Nachenberg , Shane A. Pereira
- Applicant: Kent E. Griffin , Carey S. Nachenberg , Shane A. Pereira
- Applicant Address: US CA Mountain View
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Mountain View
- Agency: Fenwick & West LLP
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F12/14

Abstract:
A security module detects attempted exploitations of vulnerabilities of applications executing on a computer. The security module hooks an application on the computer. The hook transfers control flow to the security module if execution reaches a hooked location. When a hook is followed, the security module saves the state of the computer and activates an analysis environment. A virtual machine within the analysis environment executes signatures that programmatically analyze the state of the computer to determine whether a vulnerability in the application is being exploited. If a signature detects an exploit, the security module blocks the exploit by skipping over the one or more instructions that constitute the exploit, terminating the application, or performing a different action. The security module reports the detected exploit attempt to the user of the client. The security module returns control flow back to the application if it does not detect an exploit.
Information query