首页> 外国专利> Automated protection against computer exploits

Automated protection against computer exploits

机译:自动化防御计算机漏洞利用

摘要

Protection of a computer system against exploits. A computer system has a memory access control arrangement in which at least write and execute privileges are enforced for allocated portions of memory. An association of the process thread and the first portion of memory is recorded. A limited access regime in which one of the write and execute privileges is disabled, is established, and is monitored for any exceptions occurring due to attempted writing or execution in violation thereof. In response to the exception being determined as a write exception, the associated process thread is looked up, and analyzed for a presence of malicious code. In response to the exception type being determined as an execute exception, the first portion of memory is analyzed for a presence of malicious code. In response to detection of a presence of malicious code, execution of the malicious code is prevented.
机译:保护计算机系统免受攻击。一种计算机系统具有存储器访问控制装置,其中至少对存储器的分配部分强制执行写和执行特权。记录进程线程和内存的第一部分的关联。建立其中禁用写和执行特权之一的受限访问机制,并对其进行监视,以监视由于尝试违反其尝试进行写或执行而引起的任何异常。响应于将异常确定为写异常,查找相关的进程线程,并分析是否存在恶意代码。响应于将异常类型确定为执行异常,分析存储器的第一部分是否存在恶意代码。响应于检测到恶意代码的存在,防止了恶意代码的执行。

著录项

  • 公开/公告号US8990934B2

    专利类型

  • 公开/公告日2015-03-24

    原文格式PDF

  • 申请/专利权人 KASPERSKY LAB ZAO;

    申请/专利号US201213648863

  • 发明设计人 MIKHAIL A. PAVLYUSHCHIK;

    申请日2012-10-10

  • 分类号G06F11/00;G06F21/00;

  • 国家 US

  • 入库时间 2022-08-21 15:18:26

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号