The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Dec. 30, 2014

Filed:

Jun. 03, 2011
Applicants:

Gaurav S. Kc, Mountain View, CA (US);

Alfred V. Aho, Chatham, NJ (US);

Inventors:

Gaurav S. Kc, Mountain View, CA (US);

Alfred V. Aho, Chatham, NJ (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/00 (2013.01); G06F 21/56 (2013.01); G06F 12/14 (2006.01); H04L 29/06 (2006.01);
U.S. Cl.
CPC ...
G06F 21/566 (2013.01); G06F 12/1491 (2013.01); G06F 2221/2101 (2013.01); G06F 2221/2105 (2013.01); G06F 2221/2141 (2013.01); G06F 2221/2149 (2013.01); H04L 63/1416 (2013.01); H04L 63/1441 (2013.01);
Abstract

A system for detecting and halting execution of malicious code includes a kernel-based system call interposition mechanism and a libc function interception mechanism. The kernel-based system call interposition mechanism detects a system call request from an application, determines a memory region from which the system call request emanates, and halts execution of the code responsible for the call request if the memory region from which the system call request emanates is a data memory region. The libc function interception mechanism maintains an alternative wrapper function for each of the relevant standard libc routines, intercepts a call from an application to one or more libc routines and redirects the call into the corresponding alternative wrapper function.


Find Patent Forward Citations

Loading…