Information security – Monitoring or scanning of software or data including attack... – Intrusion detection
Reexamination Certificate
2008-03-06
2011-11-22
Vu, Kim (Department: 2435)
Information security
Monitoring or scanning of software or data including attack...
Intrusion detection
C726S022000, C713S164000
Reexamination Certificate
active
08065734
ABSTRACT:
A method includes creating an intercept function for a tracked Dynamic Link Library (DLL) function of a Dynamic Link Library (DLL) being loaded into a suspicious module. Further, the import address table entry for the tracked DLL function is replaced with the respective address of the intercept function. In this manner, a call from the suspicious module to the tracked DLL function is intercepted by the intercept function. The suspicious module is associated with the thread presently executing and the call is passed to the tracked DLL function. Accordingly, any actions associated with the thread are attributed to the suspicious module instead of to a process containing the suspicious module.
REFERENCES:
patent: 2003/0021282 (2003-01-01), Hospodor
patent: 2003/0191969 (2003-10-01), Katsikas
patent: 2004/0015712 (2004-01-01), Szor
patent: 2005/0149726 (2005-07-01), Joshi et al.
patent: 2005/0198645 (2005-09-01), Marr et al.
patent: 2007/0136728 (2007-06-01), Saito
“Understanding the Import Address Table”, pp. 1-6 [online] . Retrieved on Feb. 26, 2008 from the Internet: <URL:http://sandsprite.com/CodeStuff/Understanding—imports.html>. No author provided.
“Dynamic-link library”, pp. 1-9 [online]. Retrieved on Feb. 27, 2008 from the Internet: <URL:http://en.wikipedia.org/wiki/Dynamic-link—library>. No author provided.
Kennedy et al., “Direct Call into System DLL Detection System and Method”, U.S. Appl. No. 12/163,747, filed Jun. 27, 2008.
Gunnison McKay & Hodgson, L.L.P.
Hodgson Serge J.
Paliwal Yogesh
Symantec Corporation
Vu Kim
LandOfFree
Code module operating system (OS) interactions intercepting... does not yet have a rating. At this time, there are no reviews or comments for this patent.
If you have personal experience with Code module operating system (OS) interactions intercepting..., we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Code module operating system (OS) interactions intercepting... will most certainly appreciate the feedback.
Profile ID: LFUS-PAI-O-4310434