A kernel layer shellcode detection method and device
A detection method and a technology at the kernel layer, applied in the field of information network security, can solve the problems of difficult detection of abnormal behavior and failure to detect attack behavior in time.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0078] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be embodied in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided for more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art.
[0079] As mentioned in the background technology, in order to bypass the ASLR technology, the shellcode needs to operate on the preset memory page where the kernel module is located to obtain the system API address. At present, there is no effective protection technology for bypassing the ASLR mechanism. This makes it difficult for the attacker's abnormal behavior to be detected, and it is impossible to discover the execution of the...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com