Method and apparatus for detecting Shellcode based on stack frame abnormity
A technology of exceptions and stack frames, applied in the computer field, can solve problems such as false alarms, achieve the effects of reducing false alarm rates, improving detection performance, and reducing system performance overhead
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0085] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without making creative efforts belong to the protection scope of the present invention.
[0086] In order to effectively detect shellcode and reduce performance overhead and false alarm rate, in the embodiment of the present invention, a corresponding stack frame chain is generated based on each specified API function, and each stack frame chain in each stack frame chain is sequentially detected. A stack frame, according to the abnormal behavior of the stack frame, including the length of the stack frame, the address of the extended ...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com