发明名称 Automated protection against computer exploits
摘要 Protection of a computer system against exploits. A computer system has a memory access control arrangement in which at least write and execute privileges are enforced for allocated portions of memory. An association of the process thread and the first portion of memory is recorded. A limited access regime in which one of the write and execute privileges is disabled, is established, and is monitored for any exceptions occurring due to attempted writing or execution in violation thereof. In response to the exception being determined as a write exception, the associated process thread is looked up, and analyzed for a presence of malicious code. In response to the exception type being determined as an execute exception, the first portion of memory is analyzed for a presence of malicious code. In response to detection of a presence of malicious code, execution of the malicious code is prevented.
申请公布号 EP2720170(A1) 申请公布日期 2014.04.16
申请号 EP20130175197 申请日期 2013.07.04
申请人 KASPERSKY LAB, ZAO 发明人 PAVLYUSHCHIK MIKHAIL
分类号 G06F21/56;G06F12/14 主分类号 G06F21/56
代理机构 代理人
主权项
地址