发明名称 Detecting return-to-LIBC buffer overflows via dynamic disassembly of offsets
摘要 A method makes use of the fact that call modules, such as APIS, making calls to a critical operating system (OS) function are typically called by a call instruction while, in contrast, a RLIBC attack typically uses call modules that are jumped to, returned to, or invoked by some means other than a call instruction. The method includes stalling a call to critical OS function and checking to ensure that the call module making the call to the critical OS function was called by a call instruction. If it is determined that the call module making the call to the critical OS function was not called by a call instruction, the method further includes taking protective action to protect a computer system.
申请公布号 US7552477(B1) 申请公布日期 2009.06.23
申请号 US20050064712 申请日期 2005.02.23
申请人 SYMANTEC CORPORATION 发明人 SATISH SOURABH;CONOVER MATTHEW
分类号 G06F12/16;G06F13/24 主分类号 G06F12/16
代理机构 代理人
主权项
地址