发明名称 Reducing false positive indications of buffer overflow attacks
摘要 Certain events, such as data input operating system calls, are likely to initiate a buffer overflow attack. A timing module generates timestamps that indicate when such possible initiating events occur. The timestamp is associated with a particular process and/or thread executing on the computer. If subsequent evidence of a buffer overflow attack is detected on the computer, the timestamps are consulted to determine if a possible initiating event occurred recently. If there is a recent initiating event, a buffer overflow attack is declared. Evidence of a buffer overflow attack can include receiving a signal from the processor indicating that the processor was asked to execute an instruction residing in non-executable memory. Evidence of a buffer overflow attack can also include detecting an action on the computer that malicious software is likely to perform, such as opening a file or network connection, being performed by an instruction residing in non-executable memory.
申请公布号 US7562391(B1) 申请公布日期 2009.07.14
申请号 US20050109215 申请日期 2005.04.18
申请人 SYMANTEC CORPORATION 发明人 NACHENBERG CAREY S.;SATISH SOURABH
分类号 G06F11/00;G06F17/30 主分类号 G06F11/00
代理机构 代理人
主权项
地址