DETECTION AND MITIGATION OF HARM FROM THE MALICIOUS CALL OF SENSITIVE CODE Russian patent published in 2018 - IPC G06F21/50 G06F21/56 

Abstract RU 2665897 C2

FIELD: information security.

SUBSTANCE: invention relates to information security. Disclosed is at least one computer readable storage medium containing one or more instructions, which, when executed by at least one processor, cause: identification of code areas in the extended page table, which includes pages of the sensitive code of the application programming interface (API) to be monitored; probing and blocking code pages that include identified areas of code, and re-mapping said code pages as soon as the extended page table being executed in an alternative form; detection of page loading, and page loading refers to a page that does not include the proper API entry point; definition, based on a page load detection related to a page that does not include the proper API entry point, from the extended page table, whether the page referred to is to be tracked; and generation, based on the definition that the page is to be monitored, the failure of execution.

EFFECT: technical result is to protect the sensitive code from attempted execution with an improper API entry point without undue cost.

19 cl, 13 dwg

Similar patents RU2665897C2

Title Year Author Number
SYSTEM AND METHOD FOR AUTOMATIC PROCESSING OF SOFTWARE SYSTEM ERRORS 2012
  • Antukh Aleksandr Ehduardovich
  • Malanov Aleksej Vladimirovich
RU2521265C2
PROGRAMMING INTERFACE FOR COMPUTING PLATFORM 2004
  • Bogdan Dzheffri L.
  • Relaja Robert A.
RU2365978C2
METHOD OF COMMUNICATION TRANSMISSION BETWEEN ADDRESS SPACES 2016
  • Pintijskij Vladislav Valerevich
  • Anikin Denis Vyacheslavovich
  • Kirsanov Dmitrij Aleksandrovich
RU2634172C1
SYSTEM AND METHOD OF DETECTING MALICIOUS CODE IN FILE 2016
  • Golovkin Maksim Yurevich
  • Monastyrskij Aleksej Vladimirovich
  • Pintijskij Vladislav Valerevich
  • Pavlyushchik Mikhail Aleksandrovich
  • Butuzov Vitalij Vladimirovich
  • Karasovskij Dmitrij Valerievich
RU2637997C1
METHOD OF IMPLEMENTATING INSTRUCTIONS IN SYSTEMIC MEMORY 2016
  • Pintijskij Vladislav Valerevich
  • Kirsanov Dmitrij Aleksandrovich
  • Anikin Denis Vyacheslavovich
RU2623883C1
DEBUGGING NATIVE CODE BY TRANSITIONING FROM EXECUTION IN NATIVE MODE TO EXECUTION IN INTERPRETED MODE 2014
  • Koltachev, Mikhail
  • Khandelval, Nikkhil
  • Gandi, Akrosh
RU2668973C2
METHOD FOR TRANSFER OF CONTROL BETWEEN MEMORY AREAS 2014
  • Pintijskij Vladislav Valerevich
  • Kirsanov Dmitrij Aleksandrovich
  • Anikin Denis Vjacheslavovich
RU2580016C1
AUTHENTICITY DISPLAY FROM HIGHLY RELIABLE MEDIUM TO NON-SECURE MEDIUM 2004
  • Uilmehn Brajan Mark
  • Inglend Pol
  • Rej Kennet D.
  • Kaplan Kejt
  • Kurien Varugis
  • Marr Majkl Dehvid
RU2390836C2
CLOUD SERVICE SECURITY BROKER AND PROXY 2014
  • Koem Aviram
  • Mojsi Liran
  • Lyuttvak Ami
  • Reznik Roj
  • Vishnepolski Greg
RU2679549C2
EMULATOR AND METHOD FOR EMULATION 2020
  • Pintijskij Vladislav Valerevich
  • Anikin Denis Vyacheslavovich
  • Kirsanov Dmitrij Aleksandrovich
  • Trofimenko Sergej Vladimirovich
RU2757409C1

RU 2 665 897 C2

Authors

Sahita Ravi

Deng Lu

Shanbhogue Vedvyas

Lu Lixin

Shepsen Alexander

Tatourian Igor

Dates

2018-09-04Published

2015-08-26Filed