Invention Grant
- Patent Title: Systems and methods for monitoring programs
- Patent Title (中): 监测程序的系统和方法
-
Application No.: US14585233Application Date: 2014-12-30
-
Publication No.: US09552481B1Publication Date: 2017-01-24
- Inventor: Fanglu Guo
- Applicant: Symantec Corporation
- Applicant Address: US CA Mountain View
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Mountain View
- Agency: Fisherbroyles LLP
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F21/53 ; G06F21/54

Abstract:
A computer-implemented method for monitoring programs may include (1) placing a program within an enclave that includes a protected address space that code outside of the protected address space is restricted from accessing, (2) hooking an application programming interface call within the program in the enclave to monitor the behavior of the program, (3) inserting an enclave entry instruction into code outside of the protected address space that the program accesses through the hooking of the application programming interface call, and (4) monitoring the behavior of the program by executing the program within the enclave in an attempt to force the program to use the hooked application programming interface call in order to access data outside the enclave. Various other methods, systems, and computer-readable media are also disclosed.
Information query