Application Protection via DLL Legitimacy Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional methods fail to detect and defend against indirect attacks that use system processes as a trampoline for malicious activities, such as dll injection and code modification, which exploit legal system processes to bypass security measures.
Innovation Solution
A method that intercepts process opening requests, analyzes the start address of dlls or modified codes, and uses cloud verdict services or antivirus engines to verify their legitimacy, employing API hooks and disassembly to differentiate between legal and malicious access attempts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional callback interception methods are used to verify process context, then legal system processes can access protected applications, but malicious attacks using system processes as trampolines cannot be detected
Solution Approach 1:
The patent applies preliminary action by analyzing and verifying the legitimacy of code modules (DLLs, executables) before they are allowed to access protected applications. The system pre-establishes a verification mechanism that checks the origin and authenticity of code modules attempting to open protected processes, rather than relying solely on process context verification. This prevents malicious code from exploiting legal system processes as trampolines, while still allowing legitimate access.
2Ease of operation
If process context verification is performed on intercepted calls, then basic application features can function, but indirect attacks through injected DLLs remain undetected
Solution Approach 1:
The patent introduces an intermediary verification mechanism that acts as a mediator between the code module and the protected application. Instead of directly verifying process context, the system introduces a code module verification step that checks the legitimacy of the intermediary (DLL, executable) attempting to access the protected process. This intermediary verification layer detects injected DLLs and modified codes while allowing legitimate code modules to pass through, thus maintaining ease of operation for basic features while improving detection capability.
3Adaptability or versatility
If read/write access is opened to protected applications, then system processes can perform privilege management and skin painting, but malware can read private data and modify codes
Solution Approach 1:
The patent applies local quality by implementing different access control policies for different code modules. Instead of uniformly allowing or blocking all access to protected applications, the system verifies each code module's legitimacy individually. Legitimate system processes (svchost.exe, privilege management components, skin painting components) are allowed to access protected applications, while malicious code modules are blocked. This selective verification approach maintains the necessary adaptability for system components while preventing harmful factors from affecting the protected application.
Data Source
AI summary
There is provided a method to protect applications running in a hostile environment, including against trampoline based attacks which use dll injection and code modification. The method includes protecting an application when access is performed from injected dll, and protecting the application when access is performed from modified codes.


