发明名称 SYSTEM AND METHOD FOR FOREIGN CODE DETECTION.
摘要 <p>A method and system for efficient foreign code detection is presented. In one aspect of the invention, an authentication module examines pages which are referenced by thread stacks in a process space, where the pages may contain foreign code. The module can walk up the thread stacks to examine return address that reference such pages. In another aspect, the module checks random pages referenced by the stack. In yet another aspect, the module checks any nearby suspicious pages to checked pages referenced by the stack. Additionally, the module checks the instruction pointer referenced page, the pages and calling code described by the page fault history, and any pages with event handling functions, dynamic link library functions, or other functions that are likely to run.</p>
申请公布号 MX2007011026(A) 申请公布日期 2007.09.26
申请号 MX20070011026 申请日期 2006.04.06
申请人 MICROSOFT CORPORATION. 发明人 KRISTJAN HATLELID;URI LONDON;VLADIMIR A. SHUBIN
分类号 G06F9/44 主分类号 G06F9/44
代理机构 代理人
主权项
地址