发明名称 Enforcing the execution exception to prevent packers from evading the scanning of dynamically created code
摘要 To detect possible malicious code that is unpacked at runtime before it is executed, antivirus software requires that any dynamically created code be scanned before it can be executed by a host computer system. This requirement may be enforced by requiring memory pages to be either executable or writable, but not both. Before changing from writable but not executable to executable but not writable, the page is scanned for malicious code. To prevent packers from evading this scanning, the software may enforce the execution exception to prevent packers from changing whether a page is executable and thereby evading the scanning of dynamically created code. The software may also include exception handlers to allow a program to write to a page that contains the code being executed, but also limit such an operation (e.g., to a single step) to avoid evasion of the antivirus software.
申请公布号 US8510828(B1) 申请公布日期 2013.08.13
申请号 US20070967529 申请日期 2007.12.31
申请人 GUO FANGLU;CHIUEH TZI-CKER;SYMANTEC CORPORATION 发明人 GUO FANGLU;CHIUEH TZI-CKER
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址