发明名称 Shell code blocking system and method
摘要 A method includes hooking a critical operating system function, originating a call to the critical operating system function with a call module of a parent application, stalling the call, determining a location of the call module in memory, and determining whether the location is in an executable area of the memory. Upon a determination that the call module is not in the executable area, the method further includes terminating the call. By terminating the call, execution of a child application that would otherwise allow unauthorized remote access is prevented.
申请公布号 US2004158729(A1) 申请公布日期 2004.08.12
申请号 US20030360341 申请日期 2003.02.06
申请人 SYMANTEC CORPORATION 发明人 SZOR PETER
分类号 G06F21/00;(IPC1-7):H04L9/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址