发明名称 Changing code execution path using kernel mode redirection
摘要 A mechanism for redirecting a code execution path in a running process. A one-byte interrupt instruction (e.g., INT 3 ) is inserted into the code path. The interrupt instruction passes control to a kernel handler, which after executing a replacement function, returns to continue executing the process. The replacement function resides in a memory space that is accessible to the kernel handler. The redirection mechanism may be applied without requiring a reboot of the computing device on which the running process is executing. In addition, the redirection mechanism may be applied without overwriting more than one byte in the original code.
申请公布号 US2007011686(A1) 申请公布日期 2007.01.11
申请号 US20050177079 申请日期 2005.07.08
申请人 MICROSOFT CORPORATION 发明人 BEN-ZVI NIR
分类号 G06F3/00 主分类号 G06F3/00
代理机构 代理人
主权项
地址