发明名称 EXECUTABLE COMPONENT INJECTION UTILIZING HOTPATCH MECHANISMS
摘要 Techniques for causing a component loader associated with a hotpatch mechanism to execute a user-mode component which, when executed, creates a user-mode process, thread, or held reference are described herein. The component may further indicate to the component loader that it lacks hotpatch data, causing the component loader to unload the component. In some implementations, a kernel-mode module may initially provide the component to the hotpatch mechanism with an entrypoint of the component set to zero and with hotpatch data for the component loader. The hotpatch mechanism may apply the hotpatch data, modifying the component loader such that the component loader requests execute rights for a section object for the component. The kernel-mode module may then set the entrypoint such that the component becomes executable, and provides the section object and component to the hotpatch mechanism to cause the component loader to execute the component.
申请公布号 WO2014172182(A8) 申请公布日期 2015.12.17
申请号 WO2014US33661 申请日期 2014.04.10
申请人 CROWDSTRIKE, INC. 发明人 IONESCU, ION-ALEXANDRU
分类号 G06F21/50 主分类号 G06F21/50
代理机构 代理人
主权项
地址