首页> 外国专利> Protection of computers against argument switch attacks

Protection of computers against argument switch attacks

机译:保护计算机免受参数切换攻击

摘要

A computer is protected from argument switch attacks by intercepting a function call to terminate a process. The function call and a handle used as an argument in the function call are forwarded by an antivirus system service descriptor table to an antivirus. The antivirus is configured to evaluate the function call to determine whether or not the function call is terminating an antivirus process. A consistent handle table includes a listing of handles of processes employed as arguments in function calls that terminate processes and are approved by the antivirus. Instructions that close a handle are detected by the antivirus, which compares the handle to those in the consistent handle table. The antivirus blocks those instructions that close a handle that is included in the consistent handle table.
机译:通过拦截终止进程的函数调用,可以保护计算机免受参数切换攻击。防病毒系统服务描述符表将功能调用和用作功能调用参数的句柄转发给防病毒软件。防病毒程序配置为评估功能调用以确定该功能调用是否正在终止防病毒进程。一致的句柄表包括进程的句柄列表,这些进程的句柄用作函数调用中的参数,这些函数终止进程并得到防病毒软件的认可。防病毒程序会检测到关闭句柄的指令,将其与一致的句柄表中的句柄进行比较。防病毒软件会阻止那些关闭一致句柄表中包含的句柄的指令。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号