首页> 外国专利> Buffer overflow exploit detection

Buffer overflow exploit detection

机译:缓冲区溢出漏洞检测

摘要

A call to a memory management application programming interface (API) that results in a buffer overflow due to inaccurate bounds checking could potentially leave the system vulnerable to being exploited by a third party. Approaches presented herein can monitor calls to these APIs in order to determine typical memory sizes passed to these APIs. During an initial baselining period a number of profiles are generated that indicate expected memory size parameters under various different call conditions, such from specific sources or call stacks. Comparing subsequently received API calls against the expected values from the relevant profile enables the legitimacy of an API call to be determined with relatively high accuracy. A suspicious call is identified based at least in part upon determining that the memory size of the call falls outside an expected range for that API and the relevant context.
机译:调用内存管理应用程序编程接口(API)会由于不正确的边界检查而导致缓冲区溢出,从而有可能使系统容易受到第三方的利用。本文提出的方法可以监视对这些API的调用,以确定传递给这些API的典型内存大小。在初始基准期间,会生成许多配置文件,这些配置文件指示在各种不同的调用条件(例如来自特定来源或调用堆栈)下的预期内存大小参数。将随后接收到的API调用与来自相关配置文件的期望值进行比较,可以以相对较高的精度确定API调用的合法性。至少部分地基于确定该呼叫的存储器大小落在该API和相关上下文的预期范围之外来识别可疑呼叫。

著录项

  • 公开/公告号US9892253B1

    专利类型

  • 公开/公告日2018-02-13

    原文格式PDF

  • 申请/专利权人 AMAZON TECHNOLOGIES INC.;

    申请/专利号US201615187006

  • 发明设计人 NIMA SHARIFI MEHR;

    申请日2016-06-20

  • 分类号G06F21;G06F21/52;

  • 国家 US

  • 入库时间 2022-08-21 12:57:50

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号