Invention Grant
US08484753B2 Hooking nonexported functions by the offset of the function 有权
通过函数的偏移来挂接不输出的函数

  • Patent Title: Hooking nonexported functions by the offset of the function
  • Patent Title (中): 通过函数的偏移来挂接不输出的函数
  • Application No.: US12629330
    Application Date: 2009-12-02
  • Publication No.: US08484753B2
    Publication Date: 2013-07-09
  • Inventor: Daisuke Nojiri
  • Applicant: Daisuke Nojiri
  • Applicant Address: US CA Santa Clara
  • Assignee: McAfee, Inc.
  • Current Assignee: McAfee, Inc.
  • Current Assignee Address: US CA Santa Clara
  • Agency: Patent Capital Group
  • Main IPC: G06F21/00
  • IPC: G06F21/00
Hooking nonexported functions by the offset of the function
Abstract:
Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for obfuscated malware. In one aspect, a method includes accessing offset data associated with a binary executable, the offset data including an offset of a nonexported function; and modifying instructions at the offset. In another aspect, a method includes analyzing a reference generated for a binary executable, identifying a unique identifier for the binary executable, determining an offset of a nonexported function in the binary executable, and generating offset data that includes the offset and the unique identifier.
Public/Granted literature
Information query
Patent Agency Ranking
0/0