US2015089651A1PendingUtilityA1

Methods of detection of software exploitation

Assignee: ESET SPOL S R OPriority: Jul 15, 2013Filed: Dec 2, 2014Published: Mar 26, 2015
Est. expiryJul 15, 2033(~7 yrs left)· nominal 20-yr term from priority
G06F 21/566G06F 21/56G06F 2221/033
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for detecting software exploitation broadly comprises the steps of gathering information about processes and threads executing on a computing device, monitoring instructions executed by a thread that is currently running, performing the following steps if a function to create a process or a function to load a library is called, examining a thread information block, determining whether an address included in a stack pointer of the thread is in a range of addresses for a stack specified by the thread information block, and determining whether a first plurality of no-operation instructions is followed by shell code that is followed by a second plurality of no-operation instructions.

Claims

exact text as granted — not AI-modified
Having thus described various embodiments of the invention, what is claimed as new and desired to be protected by Letters Patent includes the following: 
     
         1 . A non-transitory computer-readable storage medium with an executable program stored thereon for detecting software exploitation, wherein the program instructs a processing element to perform the following steps:
 gathering information about processes and threads executing on a computing device;   monitoring instructions executed by a thread that is currently running; and   performing the following steps when a function to create a process or a function to load a library is called
 examining a plurality of items on a stack, 
 examining a chain of exception handlers, each exception handler including a first address pointing to the next exception handler and a second address pointing to instructions for handling an exception, and 
 determining for each exception handler whether the second address is located in an address space for executable code. 
   
     
     
         2 . The computer-readable storage medium of  claim 1 , wherein the program further comprises the step of displaying a message to a user that a possible software exploit has been detected when any one of the second addresses is not located in the address space for executable code. 
     
     
         3 . The computer-readable storage medium of  claim 1 , wherein the program further comprises the step of determining for each exception handler whether the first address is within the stack. 
     
     
         4 . The computer-readable storage medium of  claim 3 , wherein the program further comprises the step of displaying a message to a user that a possible software exploit has been detected when any one of the first addresses is not located within the stack. 
     
     
         5 . The computer-readable storage medium of  claim 1 , wherein the program further comprises the step of determining for each exception handler whether the first address points to a previous exception handler. 
     
     
         6 . The computer-readable storage medium of  claim 5 , wherein the program further comprises the step of displaying a message to a user that a possible software exploit has been detected when any one of the first addresses points to a previous exception handler. 
     
     
         7 . A non-transitory computer-readable storage medium with an executable program stored thereon for detecting software exploitation, wherein the program instructs a processing element to perform the following steps:
 gathering information about processes and threads executing on a computing device;   monitoring instructions executed by a thread that is currently running; and   performing the following steps when a function to create a process or a function to load a library is called
 examining a plurality of items on a stack, 
 examining a chain of exception handlers, each exception handler including a first address pointing to the next exception handler and a second address pointing to instructions for handling an exception, 
 determining for each exception handler whether the first address is within the stack, 
 determining for each exception handler whether the first address points to a previous exception handler, and 
 determining for each exception handler whether the second address is located in an address space for executable code. 
   
     
     
         8 . The computer-readable storage medium of  claim 7 , wherein the program further comprises the step of displaying a message to a user that a possible software exploit has been detected when any one of the first addresses is not located within the stack. 
     
     
         9 . The computer-readable storage medium of  claim 7 , wherein the program further comprises the step of displaying a message to a user that a possible software exploit has been detected when any one of the first addresses points to a previous exception handler. 
     
     
         10 . The computer-readable storage medium of  claim 7 , wherein the program further comprises the step of displaying a message to a user that a possible software exploit has been detected when any one of the second addresses is not located in the address space for executable code. 
     
     
         11 . A computing device for detecting software exploitation, the computing device comprising:
 a processing element coupled to a memory element, wherein the processing element is configured to detect software exploitation by:
 gathering information about processes and threads executing on a computing device; 
 monitoring instructions executed by a thread that is currently running; and 
 performing the following steps when a function to create a process or a function to load a library is called
 examining a plurality of items on a stack, 
 examining a chain of exception handlers, each exception handler including a first address pointing to the next exception handler and a second address pointing to instructions for handling an exception, and 
 determining for each exception handler whether the second address is located in an address space for executable code. 
 
   
     
     
         12 . The computing device of  claim 11 , wherein the processing element is further configured to detect software exploitation by displaying a message to a user that a possible software exploit has been detected when any one of the second addresses is not located in the address space for executable code. 
     
     
         13 . The computing device of  claim 11 , wherein the processing element is further configured to detect software exploitation by determining for each exception handler whether the first address is within the stack. 
     
     
         14 . The computing device of  claim 13 , wherein the processing element is further configured to detect software exploitation by displaying a message to a user that a possible software exploit has been detected when any one of the first addresses is not located within the stack. 
     
     
         15 . The computing device of  claim 11 , wherein the processing element is further configured to detect software exploitation by determining for each exception handler whether the first address points to a previous exception handler. 
     
     
         16 . The computing device of  claim 15 , wherein the processing element is further configured to detect software exploitation by displaying a message to a user that a possible software exploit has been detected when any one of the first addresses points to a previous exception handler.

Join the waitlist — get patent alerts

Track US2015089651A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.