发明授权
- 专利标题: Methods, systems, articles of manufacture and apparatus to detect process hijacking
-
申请号: US16246187申请日: 2019-01-11
-
公开(公告)号: US11416603B2公开(公告)日: 2022-08-16
- 发明人: Zheng Zhang , Jason Martin , Justin Gottschlich , Abhilasha Bhargav-Spantzel , Salmin Sultana , Li Chen , Wei Li , Priyam Biswas , Paul Carlson
- 申请人: Intel Corporation
- 申请人地址: US CA Santa Clara
- 专利权人: Intel Corporation
- 当前专利权人: Intel Corporation
- 当前专利权人地址: US CA Santa Clara
- 代理机构: Hanley, Flight & Zimmerman, LLC
- 主分类号: G06F21/52
- IPC分类号: G06F21/52 ; G06N20/00 ; G06F21/56 ; G06F21/51 ; G05B23/02
摘要:
Methods, systems, articles of manufacture and apparatus to detect process hijacking are disclosed herein. An example apparatus to detect control flow anomalies includes a parsing engine to compare a target instruction pointer (TIP) address to a dynamic link library (DLL) module list, and in response to detecting a match of the TIP address to a DLL in the DLL module list, set a first portion of a normalized TIP address to a value equal to an identifier of the DLL. The example apparatus disclosed herein also includes a DLL entry point analyzer to set a second portion of the normalized TIP address based on a comparison between the TIP address and an entry point of the DLL, and a model compliance engine to generate a flow validity decision based on a comparison between (a) the first and second portion of the normalized TIP address and (b) a control flow integrity model.
公开/授权文献
信息查询