首页> 外国专利> POST SANDBOX METHODS AND SYSTEMS FOR DETECTING AND BLOCKING ZERO-DAY EXPLOITS VIA API CALL VALIDATION

POST SANDBOX METHODS AND SYSTEMS FOR DETECTING AND BLOCKING ZERO-DAY EXPLOITS VIA API CALL VALIDATION

机译:POST沙盒方法和系统,通过API呼叫验证来检测和阻止零日开发

摘要

In one aspect, a method useful for monitoring and validating execution of executable binary code, includes the step of disassembling an executable binary code of an application. The method includes the step of detecting and obtaining location and type of an application programming interface (API) call, system call, and privileged instruction that is executed by the executable binary code. The method includes the step of detecting and obtaining return address from an Al call and system call. The method includes the step of validating location of the API call system call, and privileged instruction. The method includes the step of validating return from the API call and system call.
机译:在一个方面,一种用于监视和验证可执行二进制代码的执行的方法,包括拆卸应用程序的可执行二进制代码的步骤。该方法包括以下步骤:检测并获得应用程序接口(API)调用,系统调用和由可执行二进制代码执行的特权指令的位置和类型。该方法包括从A1呼叫和系统呼叫中检测并获得返回地址的步骤。该方法包括验证API调用系统调用的位置和特权指令的步骤。该方法包括验证来自API调用和系统调用的返回的步骤。

著录项

  • 公开/公告号US2019138715A1

    专利类型

  • 公开/公告日2019-05-09

    原文格式PDF

  • 申请/专利权人 JAYANT SHUKLA;

    申请/专利号US201715807582

  • 发明设计人 JAYANT SHUKLA;

    申请日2017-11-09

  • 分类号G06F21/54;G06F9/54;G06F21/56;G06F21/53;

  • 国家 US

  • 入库时间 2022-08-21 12:04:55

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号