Methods of detection of software exploitation
Abstract
A method for detecting software exploitation broadly comprises the steps of gathering information about processes and threads executing on a computing device, monitoring instructions executed by a thread that is currently running, performing the following steps if a function to create a process or a function to load a library is called, examining a thread information block, determining whether an address included in a stack pointer of the thread is in a range of addresses for a stack specified by the thread information block, and determining whether a first plurality of no-operation instructions is followed by shell code that is followed by a second plurality of no-operation instructions.
Claims
exact text as granted — not AI-modified1 . A non-transitory computer-readable storage medium with an executable program stored thereon for detecting software exploitation, wherein the program instructs a processing element to perform the following steps:
gathering information about processes, threads, and applets executing on a computing device; monitoring instructions executed by processes, threads, and applets that are currently running; utilizing a programming interface; and determining whether a system.setsecuritymanager(null) call is made followed by a processbuilder.start( )call.
2 . The computer-readable storage medium of claim 1 , wherein the program further comprises the step of displaying a message to a user that a possible software exploit has been detected when the system.setsecuritymanager(null) call is made followed by the processbuilder.start( ) call.
3 . A non-transitory computer-readable storage medium with an executable program stored thereon for detecting software exploitation, wherein the program instructs a processing element to perform the following steps:
gathering information about processes, threads, and applets executing on a computing device; monitoring instructions executed by processes, threads, and applets that are currently running; utilizing a programming interface; determining whether a system.setsecuritymanager(null) call is made followed by a processbuilder.start( ) call; and displaying a message to a user that a possible software exploit has been detected when the system.setsecuritymanager(null) call is made followed by the processbuilder.start( ) call.
4 . A computing device for detecting software exploitation, the computing device comprising:
a processing element coupled to a memory element, wherein the processing element is configured to detect software exploitation by: gathering information about processes, threads, and applets executing on a computing device; monitoring instructions executed by processes, threads, and applets that are currently running; utilizing a programming interface; and determining whether a system.setsecuritymanager(null) call is made followed by a processbuilder.start( ) call.
5 . The computing device of claim 4 , wherein the processing element is further configured to detect software exploitation by displaying a message to a user that a possible software exploit has been detected when the system.setsecuritymanager(null) call is made followed by the processbuilder.start( ) call.Join the waitlist — get patent alerts
Track US2015089653A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.