US2015089652A1PendingUtilityA1

Methods of detection of software exploitation

Assignee: ESET SPOL S R OPriority: Jul 15, 2013Filed: Dec 2, 2014Published: Mar 26, 2015
Est. expiryJul 15, 2033(~7 yrs left)· nominal 20-yr term from priority
G06F 21/56G06F 21/566G06F 2221/033
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for detecting software exploitation broadly comprises the steps of gathering information about processes and threads executing on a computing device, monitoring instructions executed by a thread that is currently running, performing the following steps if a function to create a process or a function to load a library is called, examining a thread information block, determining whether an address included in a stack pointer of the thread is in a range of addresses for a stack specified by the thread information block, and determining whether a first plurality of no-operation instructions is followed by shell code that is followed by a second plurality of no-operation instructions.

Claims

exact text as granted — not AI-modified
1 . A non-transitory computer-readable storage medium with an executable program stored thereon for detecting software exploitation, wherein the program instructs a processing element to perform the following steps:
 gathering information about processes, threads, and applets executing on a computing device;   monitoring instructions executed by processes, threads, and applets that are currently running;   monitoring any file that is created by the applets;   determining whether the file is being executed as an additional process; and   determining whether the file is being loaded as a library.   
     
     
         2 . The computer-readable storage medium of  claim 1 , wherein the program further comprises the step of displaying a message to a user that a possible software exploit has been detected when the file is being executed as an additional process. 
     
     
         3 . The computer-readable storage medium of  claim 1 , wherein the program further comprises the step of displaying a message to a user that a possible software exploit has been detected when the file is being loaded as a library. 
     
     
         4 . A non-transitory computer-readable storage medium with an executable program stored thereon for detecting software exploitation, wherein the program instructs a processing element to perform the following steps:
 gathering information about processes, threads, and applets executing on a computing device;   monitoring instructions executed by processes, threads, and applets that are currently running;   monitoring any file that is created by the applets;   determining whether the file is being executed as an additional process;   displaying a message to a user that a possible software exploit has been detected when the file is being executed as an additional process;   determining whether the file is being loaded as a library; and   displaying a message to a user that a possible software exploit has been detected when the file is being loaded as a library.   
     
     
         5 . A computing device for detecting software exploitation, the computing device comprising:
 a processing element coupled to a memory element, wherein the processing element is configured to detect software exploitation by:
 gathering information about processes, threads, and applets executing on a computing device; 
 monitoring instructions executed by processes, threads, and applets that are currently running; 
 monitoring any file that is created by the applets; 
 determining whether the file is being executed as an additional process; and 
 determining whether the file is being loaded as a library. 
   
     
     
         6 . The computing device of  claim 5 , wherein the processing element is further configured to detect software exploitation by displaying a message to a user that a possible software exploit has been detected when the file is being executed as an additional process. 
     
     
         7 . The computing device of  claim 5 , wherein the processing element is further configured to detect software exploitation by displaying a message to a user that a possible software exploit has been detected when the file is being loaded as a library.

Join the waitlist — get patent alerts

Track US2015089652A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.