发明名称 Methods for hooking applications to monitor and prevent execution of security-sensitive operations
摘要 The present invention discloses methods and media for hooking applications to monitor and prevent execution of security-sensitive operations, the method including the steps of: reading at least one configuration parameter list from a configuration module; hooking, by a hooking engine, a hooking point in an application, wherein the hooking point is defined in the configuration module; calling, by the application, the hooking point during operation of the application; matching at least one hooking parameter in the hooking point to at least one configuration parameter in at least one configuration parameter list; and upon detecting a match between the hooking parameter and at least one configuration parameter, performing at least one configuration-defined action. Preferably, the method further includes the step of: updating a state of the hooking engine. Preferably, the hooking engine is operative to prevent malicious operations by obfuscated code.
申请公布号 US7930744(B2) 申请公布日期 2011.04.19
申请号 US20080166341 申请日期 2008.07.02
申请人 CHECK POINT SOFTWARE TECHNOLOGIES LTD. 发明人 TELLER TOMER;NAHOUM IDAN;ZEGMAN TAMIR
分类号 G06F11/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址