会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 6. 发明授权
    • Detecting return-to-LIBC buffer overflows via dynamic disassembly of offsets
    • 通过动态反汇编来检测返回LIBC缓冲区溢出
    • US07552477B1
    • 2009-06-23
    • US11064712
    • 2005-02-23
    • Sourabh SatishMatthew Conover
    • Sourabh SatishMatthew Conover
    • G06F12/16G06F13/24
    • G06F21/52G06F9/545G06F2209/542
    • A method makes use of the fact that call modules, such as APIS, making calls to a critical operating system (OS) function are typically called by a call instruction while, in contrast, a RLIBC attack typically uses call modules that are jumped to, returned to, or invoked by some means other than a call instruction. The method includes stalling a call to critical OS function and checking to ensure that the call module making the call to the critical OS function was called by a call instruction. If it is determined that the call module making the call to the critical OS function was not called by a call instruction, the method further includes taking protective action to protect a computer system.
    • 一种方法利用呼叫模块(例如APIS)调用关键操作系统(OS)功能的事实通常由调用指令调用,而相比之下,RLIBC攻击通常使用跳转到的调用模块, 通过某种方式返回或调用,而不是通话指令。 该方法包括停止对关键OS功能的调用,并检查以确保通过调用指令调用对关键OS功能进行调用的调用模块。 如果确定对呼叫指令进行调用的呼叫模块未被呼叫指令调用,则该方法还包括采取保护措施来保护计算机系统。
    • 9. 发明授权
    • System and method for locating a memory page in a guest virtual machine
    • 用于在guest虚拟机中定位内存页的系统和方法
    • US08838913B1
    • 2014-09-16
    • US12560036
    • 2009-09-15
    • Matthew Conover
    • Matthew Conover
    • G06F12/00G06F9/44G06F9/455G06F12/08
    • G06F12/08G06F9/45558G06F2009/45583G06F2212/151
    • A system and method for locating a memory page in a guest virtual machine are provided. An execution event is triggered, in response to a request to allocate a first memory page in a virtual machine. A processor sends an indication to a hypervisor that the first memory page has been allocated in the virtual machine, in response to the triggering of the execution event. Responsive to receiving the indication, a security virtual machine appropriates control, via the hypervisor, of the first memory page allocated in the virtual machine and inserts program code in the first memory page. The processor executes the program code. The security virtual machine relinquishes control of the first memory page allocated in the virtual machine, in response to determining the program code has completed execution.
    • 提供了一种用于定位客虚拟机中的存储器页面的系统和方法。 响应于在虚拟机中分配第一内存页的请求,触发执行事件。 响应于触发执行事件,处理器向管理程序发送指示已经在虚拟机中分配了第一存储器页面。 响应于接收到该指示,安全虚拟机通过虚拟机管理程序对分配在虚拟机中的第一存储器页面进行控制,并将程序代码插入到第一存储器页面中。 处理器执行程序代码。 响应于确定程序代码已经完成执行,安全虚拟机放弃在虚拟机中分配的第一内存页的控制。