发明名称 SYSTEMS AND METHODS FOR DETECTING RETURN-ORIENTED PROGRAMMING (ROP) EXPLOITS
摘要 Described systems and methods allow protecting a computer system from malware, such as return-oriented programming (ROP) exploits. In some embodiments, a set of references are identified within a call stack used by a thread of a target process, each reference pointing into the memory space of an executable module loaded by the target process. Each such reference is analyzed to determine whether it points to a ROP gadget, and whether the respective reference was pushed on the stack by a legitimate function call. In some embodiments, a ROP score is indicative of whether the target process is subject to a ROP attack, the score determined according to a count of references to a loaded module, according to a stack footprint of the respective module, and further according to a count of ROP gadgets identified within the respective module.
申请公布号 WO2015119522(A2) 申请公布日期 2015.08.13
申请号 WO2014RO50002 申请日期 2014.11.03
申请人 BITDEFENDER IPR MANAGEMENT LTD 发明人 TOSA, RAUL-VASILE
分类号 主分类号
代理机构 代理人
主权项
地址