- 专利标题: Malicious code protection for computer systems based on process modification
-
申请号: US15324656申请日: 2015-05-08
-
公开(公告)号: US10528735B2公开(公告)日: 2020-01-07
- 发明人: Michael Gorelik , Mordechai Guri , David Mimran , Gabriel Kedma , Ronen Yehoshua
- 申请人: MORPHISEC INFORMATION SECURITY 2014 LTD.
- 申请人地址: IL Beer Sheva
- 专利权人: Morphisec Information Security 2014 Ltd.
- 当前专利权人: Morphisec Information Security 2014 Ltd.
- 当前专利权人地址: IL Beer Sheva
- 代理机构: Fiala & Weaver P.L.L.C.
- 国际申请: PCT/IB2015/053394 WO 20150508
- 国际公布: WO2016/079602 WO 20160526
- 主分类号: G06F21/56
- IPC分类号: G06F21/56 ; G06F21/52 ; G06F21/54
摘要:
Various approaches are described herein for, among other things, detecting and/or neutralizing attacks by malicious code. For example, instance(s) of a protected process are modified upon loading by injecting a runtime protector that creates a copy of each of the process' imported libraries and maps the copy into a random address inside the process' address space to form a “randomized” shadow library. The libraries loaded at the original address are modified into a stub library. Shadow and stub libraries are also created for libraries that are loaded after the process creation is finalized. Consequently, when malicious code attempts to retrieve the address of a given procedure, it receives the address of the stub procedure, thereby neutralizing the malicious code. When the original program's code (e.g., the non-malicious code) attempts to retrieve the address of a procedure, it receives the correct address of the requested procedure (located in the shadow library).
公开/授权文献
信息查询