发明名称 Operating system loader modification
摘要 Systems and methods for computer security are provided. In one implementation, a computer-implemented method is provided. The method includes applying a hook to a kernel of an operating system, monitoring system calls made to the kernel using the hook, and injecting a new entry into a list of files assembled by a loader to create a new process when the hook identifies a create process system call. In another implementation, the method can further include initializing the injected new entry where the injected new entry is operable to examine process files prior to loading, examining the process files, and acting on the process according to a result of the examination.
申请公布号 US7707558(B2) 申请公布日期 2010.04.27
申请号 US20050150815 申请日期 2005.06.10
申请人 SYMANTEC CORPORATION 发明人 YEAP YUEN-PIN;LAWRENCE PAUL DANIEL
分类号 G06F9/44;G06F12/16 主分类号 G06F9/44
代理机构 代理人
主权项
地址
您可能感兴趣的专利