Methods of detection of software exploitation
Abstract
A method for detecting software exploitation broadly comprises the steps of gathering information about processes and threads executing on a computing device, monitoring instructions executed by a thread that is currently running, performing the following steps if a function to create a process or a function to load a library is called, examining a thread information block, determining whether an address included in a stack pointer of the thread is in a range of addresses for a stack specified by the thread information block, and determining whether a first plurality of no-operation instructions is followed by shell code that is followed by a second plurality of no-operation instructions.
Claims
exact text as granted — not AI-modifiedHaving thus described various embodiments of the invention, what is claimed as new and desired to be protected by Letters Patent includes the following:
1 . A non-transitory computer-readable storage medium with an executable program stored thereon for detecting software exploitation, wherein the program instructs a processing element to perform the following steps:
gathering information about processes and threads executing on a computing device; monitoring instructions executed by a thread that is currently running; and performing the following steps when a function to create a process or a function to load a library is called
examining a plurality of items on a stack,
determining instructions that placed items on the stack,
determining whether the instructions include valid subroutine calls, and
determining whether the instructions are located in an address space for executable code.
2 . The computer-readable storage medium of claim 1 , wherein the program further comprises the step of displaying a message to a user that a possible software exploit has been detected when the instructions include at least one subroutine call that is not valid.
3 . The computer-readable storage medium of claim 1 , wherein the program further comprises the step of displaying a message to a user that a possible software exploit has been detected when the instructions are not located in an address space for executable code.
4 . The computer-readable storage medium of claim 1 , wherein the items placed on the stack include return addresses for subroutine calls and for each return address, examining an address before the return address and determining whether the address includes a valid subroutine call.
5 . The computer-readable storage medium of claim 4 , wherein the program further comprises the step of displaying a message to a user that a possible software exploit has been detected when the address before the return address does not include a valid subroutine call.
6 . The computer-readable storage medium of claim 1 , wherein the program further comprises the step of determining whether the stack includes a return address for a dynamic link library that created the thread.
7 . The computer-readable storage medium of claim 6 , wherein the program further comprises the step of displaying a message to a user that a possible software exploit has been detected when the stack does not include the return address for the dynamic link library that created the thread.
8 . The computer-readable storage medium of claim 1 , wherein the program further comprises the step of determining whether a first address of the stack includes a start address of the thread.
9 . The computer-readable storage medium of claim 8 , wherein the program further comprises the step of displaying a message to a user that a possible software exploit has been detected when the first address of the stack does not include the start address of the thread.
10 . A non-transitory computer-readable storage medium with an executable program stored thereon for detecting software exploitation, wherein the program instructs a processing element to perform the following steps:
gathering information about processes and threads executing on a computing device; monitoring instructions executed by a thread that is currently running; and performing the following steps when a function to create a process or a function to load a library is called
examining a plurality of items on a stack,
determining instructions that placed items on the stack,
determining whether the instructions include valid subroutine calls,
determining whether a first address of the stack includes a start address of the thread,
determining whether the stack includes a return address for a dynamic link library that created the thread, and
determining whether the instructions are located in an address space for executable code.
11 . The computer-readable storage medium of claim 10 , wherein the items placed on the stack include return addresses for subroutine calls and for each return address, examining an address before the return address and determining whether the address includes a valid subroutine call.
12 . The computer-readable storage medium of claim 11 , wherein the program further comprises the step of displaying a message to a user that a possible software exploit has been detected when the address before the return address does not include a valid subroutine call.
13 . The computer-readable storage medium of claim 10 , wherein the program further comprises the step of displaying a message to a user that a possible software exploit has been detected when the stack does not include the return address for the dynamic link library that created the thread.
14 . The computer-readable storage medium of claim 10 , wherein the program further comprises the step of displaying a message to a user that a possible software exploit has been detected when the first address of the stack does not include the start address of the thread.
15 . A computing device for detecting software exploitation, the computing device comprising:
a processing element coupled to a memory element, wherein the processing element is configured to detect software exploitation by:
gathering information about processes and threads executing on a computing device;
monitoring instructions executed by a thread that is currently running; and
performing the following steps when a function to create a process or a function to load a library is called
examining a plurality of items on a stack,
determining instructions that placed items on the stack,
determining whether the instructions include valid subroutine calls, and
determining whether the instructions are located in an address space for executable code.
16 . The computing device of claim 15 , wherein the processing element is further configured to detect software exploitation by determining whether the stack includes a return address for a dynamic link library that created the thread.
17 . The computing device of claim 15 , wherein the processing element is further configured to detect software exploitation by determining whether a first address of the stack includes a start address of the thread.
18 . The computing device of claim 15 , wherein the items placed on the stack include return addresses for subroutine calls and for each return address, examining an address before the return address and determining whether the address includes a valid subroutine call.
19 . The computing device of claim 15 , wherein the processing element is further configured to detect software exploitation by displaying a message to a user that a possible software exploit has been detected when the instructions include at least one subroutine call that is not valid.
20 . The computing device of claim 15 , wherein the processing element is further configured to detect software exploitation by displaying a message to a user that a possible software exploit has been detected when the instructions are not located in an address space for executable code.Join the waitlist — get patent alerts
Track US2015278522A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.