IP Library Granted Patent US 7,945,953
Granted Patent B1
US 7,945,953 · App. 11/176,855 · Granted May 17, 2011

Method to identify buffer overflows and RLIBC attacks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,945,953
App. No.
11/176,855
Granted
May 17, 2011
Kind
B1
Abstract

A method and system detect buffer overflows and RLIBC attacks by determining if a critical call initiating function is a “potential threat”. In one embodiment, a critical call initiating function is considered a potential threat if the value of the return address of the critical call initiating function points to a location in memory between the location of the highest Thread Environment Block (TEB) or Process Environment Block (PEB) and the location of the lowest Thread Environment Block (TEB) or PEB. In another embodiment, a critical call initiating function making a call to a predefined critical operating system function is considered a potential threat if the value of the return address of the critical call initiating function points to the beginning of a new function with a zero offset.

Claims (26)

1. A computer system implemented method for blocking a buffer overflow comprising:

a computer system;

a memory associated with the computer system;

a processor associated with the computer system, the processor associated with the computer system executing instructions for implementing at least part of the computer system implemented method for blocking a buffer overflow, the computer system implemented method for blocking a buffer overflow comprising:

stalling a call to a critical operating system (OS) function, said call to a critical operating system (OS) function being made by a critical call initiating function residing in the memory associated with the computer system;

determining whether a value of a return address of said critical call initiating function points to a location in said memory associated with the computer system that corresponds to a location in a Thread Environment Block (TEB) or a Process Environment Block (PEB) of said memory associated with the computer system;

taking protective action to protect the computer system upon a determination that said return address of said critical call initiating function does point to a location in a Thread Environment Block (TEB) or a Process Environment Block (PEB) of said memory associated with the computer system; and

allowing said call to a critical operating system (OS) function to proceed upon a determination that said return address of said critical call initiating function does not point to a location in a Thread Environment Block (TEB) or a Process Environment Block (PEB) of said memory associated with the computer system.

2. The computer system implemented method for blocking a buffer overflow of claim 1 wherein said taking protective action comprises terminating said call to a critical operating system (OS) function.

3. A system comprising:

a computer system;

a memory associated with the computer system;

a processor associated with the computer system,

means for stalling a call to a critical operating system (OS) function, said call to a critical operating system (OS) function being made by a critical call initiating function residing in the memory associated with the computer system;

means for determining whether a value of a return address of said critical call initiating function points to a location in said memory associated with the computer system that corresponds to a location in a Thread Environment Block (TEB) or a Process Environment Block (PEB) of said memory associated with the computer system;

means for taking protective action to protect the computer system upon a determination that said return address of said critical call initiating function does point to a location in a Thread Environment Block (TEB) or a Process Environment Block (PEB) of said memory associated with the computer system; and

means for allowing said call to a critical operating system (OS) function to proceed upon a determination that said return address of said critical call initiating function does not point to a location in a Thread Environment Block (TEB) or a Process Environment Block (PEB) of said memory associated with the computer system.

4. The system of claim 3 wherein said taking protective action comprises terminating said call to a critical operating system (OS) function.

5. A computer system implemented method for blocking a buffer overflow comprising:

a computer system;

a memory associated with the computer system;

a processor associated with the computer system, the processor associated with the computer system executing instructions for implementing at least part of the computer system implemented method for blocking a buffer overflow, the computer system implemented method for blocking a buffer overflow comprising:

stalling a call to a critical operating system (OS) function, the critical call operating system function being an operating system function necessary for a first application to cause execution of a second application, said call to a critical operating system (OS) function being made by a critical call initiating function residing in a the memory associated with the computer system;

determining whether a value of a return address of said critical call initiating function points to a location in said memory associated with the computer system that corresponds to a location in a Thread Environment Block (TEB) or a Process Environment Block (PEB) of said memory associated with the computer system;

taking protective action to protect the computer system upon a determination that said return address of said critical call initiating function does point to a location in a Thread Environment Block (TEB) or a Process Environment Block (PEB) of said memory associated with the computer system; and

allowing said call to a critical operating system (OS) function to proceed upon a determination that said return address of said critical call initiating function does not point to a location in a Thread Environment Block (TEB) or a Process Environment Block (PEB) of said memory associated with the computer system.

Assignments (6)
CHANGE OF NAME Recorded May 18, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 063697/0493 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Mar 5, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 052109/0186 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 6, 2005
From: SALINAS, GOVIND; CONOVER, MATTHEW; SATISH, SOURABH
To: SYMANTEC CORPORATION
Reel/Frame 016738/0976 →