首页> 外国专利> APPARATUS AND A METHOD FOR PREVENTING A VIRUS CODE EXECUTION THROUGH BUFFER OVERFLOW CONTROL, PARTICULARLY FOR DETECTING BUFFER OVERFLOW THROUGH SOFTWARE WITHOUT SUPPORTING HARDWARE

APPARATUS AND A METHOD FOR PREVENTING A VIRUS CODE EXECUTION THROUGH BUFFER OVERFLOW CONTROL, PARTICULARLY FOR DETECTING BUFFER OVERFLOW THROUGH SOFTWARE WITHOUT SUPPORTING HARDWARE

机译:用于通过缓冲区溢出控制来防止病毒代码执行的装置和方法,特别是用于在不支持硬件的情况下通过软件检测缓冲区溢出的方法

摘要

PURPOSE: An apparatus and a method for preventing a virus code execution through buffer overflow control are provided to enhance a detection rate of overflow attack for the state, buffer and global variable without recompiling and the change of an application code or an operating system.;CONSTITUTION: The execution of a kernel module or application program is detected, a code conversion unit(133) changes some of kernel or application program codes into an interrupt command. When the exception is generated by the execution of the interrupt command, a code inspection unit(135) judges the buffer overflow. When the buffer overflow is generated, a virus detection engine(137) performs virus inspection for a program execution region which is moved by the buffer overflow.;COPYRIGHT KIPO 2011
机译:目的:提供一种通过缓冲区溢出控制防止病毒代码执行的装置和方法,以提高状态,缓冲区和全局变量的溢出攻击的检测率,而无需重新编译和更改应用程序代码或操作系统。构成:检测到内核模块或应用程序的执行,代码转换单元(133)将一些内核或应用程序代码更改为中断命令。当通过执行中断命令产生异常时,代码检查单元(135)判断缓冲器溢出。当产生缓冲区溢出时,病毒检测引擎(137)对由于缓冲区溢出而移动的程序执行区域进行病毒检查。; COPYRIGHT KIPO 2011

著录项

  • 公开/公告号KR20100111518A

    专利类型

  • 公开/公告日2010-10-15

    原文格式PDF

  • 申请/专利权人 SAMSUNG ELECTRONICS CO. LTD.;

    申请/专利号KR20090029986

  • 发明设计人 LEE SUNG MIN;SUH SANG BUM;JEONG BOK DEUK;

    申请日2009-04-07

  • 分类号G06F21/00;G06F5/14;G06F9/48;G06F9/30;

  • 国家 KR

  • 入库时间 2022-08-21 18:31:43

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号