发明名称 Preventing execution of remotely injected threads
摘要 A legitimate process utilizes thread local storage (TLS) functionality to prevent a malicious thread from executing in its address space. The legitimate process includes a thread white list that identifies the entry point addresses of threads executed by the process. When executed on a computer, the process interacts with the TLS functionality provided by the computer's operating system. The operating system sends the process a message each time a new thread is executed in the process's address space. Upon receiving the message, the process determines the entry point address of the new thread and checks to see if the address is in the white list. If the thread entry point address is not in the white list, the thread is probably malicious and the process therefore terminates the thread's execution.
申请公布号 US7797702(B1) 申请公布日期 2010.09.14
申请号 US20050064923 申请日期 2005.02.22
申请人 SYMANTEC CORPORATION 发明人 FERRIE PETER
分类号 G06F9/46;G06F9/26;G06F11/30 主分类号 G06F9/46
代理机构 代理人
主权项
地址