发明名称 SYSTEM AND METHOD FOR CONTROLLING ACCESS OF MACHINE CODE TO OPERATING SYSTEM RESOURCES
摘要 Disclosed is a system and method for controlling access of a native image of a machine code to resources of an operating system of a device. An example method includes obtaining the native image of the machine code; identifying a parent assembly from which the native image was created; determining and forming a correspondence between the native image and the parent assembly based at least upon a template; in response to detecting an update to the native image, generating an updated image of the native image; determining whether there is a correspondence between the updated image of the native image and the parent assembly based at least upon the template; and in response to detecting no correspondence between the updated image of the native image and the parent assembly, restricting an access of the updated image of the native image to the resources of the operating system of the device.
申请公布号 US2016292450(A1) 申请公布日期 2016.10.06
申请号 US201615164323 申请日期 2016.05.25
申请人 AO Kaspersky Lab 发明人 Ivanov Dmitry G.;Pavlov Nikita A.;Shvetsov Dmitry V.;Gorshenin Mikhail A.
分类号 G06F21/62;G06F21/55;G06F21/57 主分类号 G06F21/62
代理机构 代理人
主权项 1. A method for controlling an access of a native image of a machine code to resources of an operating system of a device, the method comprising: obtaining, by a processor, the native image of the machine code; identifying, by the processor, a parent assembly from which the native image was created; determining and forming, by the processor, a correspondence between the native image and the parent assembly based at least upon a template; in response to detecting an update to the native image, generating, by the processor, an updated image of the native image; determining, by the processor, whether there is a correspondence between the updated image of the native image and the parent assembly based at least upon the template; and in response to detecting no correspondence between the updated image of the native image and the parent assembly, restricting, by the processor, an access of the updated image of the native image to the resources of the operating system of the device.
地址 Moscow RU