IP Library Granted Patent US 8,230,499
Granted Patent B1
US 8,230,499 · App. 12/129,170 · Granted Jul 24, 2012

Detecting and blocking unauthorized downloads

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,230,499
App. No.
12/129,170
Granted
Jul 24, 2012
Kind
B1
Abstract

A hook is set for one or more downloading functions. Subsequently, code is executed within an application process. Responsive to the executed code calling one of the hooked functions, a return address of the called function is examined. If the return address is within a heap memory area of the application process, a remedial action, such as returning an error code or displaying an alert, is taken.

Claims (30)

1. A method of preventing unauthorized download of data to a computer having a web browser process comprising a memory heap, comprising:

hooking one or more downloading functions that can be called by code executing on the computer to download data;

responsive to a hooked downloading function being called by code stored in the memory heap of the web browser process, identifying a return address of the code;

determining whether the return address is within the heap based at least in part on whether data of a page of memory corresponding to the return address were loaded from a file; and

responsive to the return address being within the heap, performing a remedial action that prevents downloading of data by the called downloading function.

2. The method of claim 1 , wherein the hooked downloading functions include a function from the group of UrlDownloadToFileA, UrlDownloadToFileW, UrlDownloadToCacheFileA, and UrlDownloadToCacheFileW.

3. The method of claim 1 , wherein the code is downloaded over a network.

4. The method of claim 1 , wherein the remedial action comprises returning an error code to the code that called the hooked downloading function.

5. The method of claim 1 , wherein the remedial action comprises displaying an alert.

6. A computer program product having a non-transitory computer-readable storage medium storing executable computer program modules for preventing unauthorized download of data to a computer having a web browser process comprising a memory heap, the modules comprising:

a hooking module for hooking one or more downloading functions that can be called by code executing on the computer to download data;

a code checking module for:

identifying a return address of code stored in the memory heap of the web browser process, responsive to the code calling one of the hooked downloading functions, and

determining whether the return address is within the heap based at least in part on whether data of a page of memory corresponding to the return address were loaded from a file; and

a remediation module for performing a remedial action that prevents downloading of data by the called downloading function, responsive to the return address being within the heap.

7. The computer program product of claim 6 , wherein the hooked downloading functions include a function from the group of UrlDownloadToFileA, UrlDownloadToFileW, UrlDownloadToCacheFileA, and UrlDownloadToCacheFileW.

8. The computer program product of claim 6 , wherein the code is downloaded over a network.

9. The computer program product of claim 6 , wherein the remedial action comprises returning an error code to the code that called the hooked downloading function.

10. The computer program product of claim 6 , wherein the remedial action comprises displaying an alert.

11. A computer adapted to prevent unauthorized download of data to a computer having a web browser process comprising a memory heap, comprising:

a computer-readable storage medium storing executable computer program modules comprising:

a hooking module for hooking one or more downloading functions that can be called by code executing on the computer to download data;

a code checking module for:

identifying a return address of code stored in the memory heap of the web browser process, responsive to the code calling one of the hooked downloading functions, and

determining whether the return address is within the heap based at least in part on whether data of a page of memory corresponding to the return address were loaded from a file; and

a remediation module for performing a remedial action that prevents downloading of data by the called downloading function, responsive to the return address being within the heap.

12. The computer of claim 11 , wherein the hooked downloading functions include a function from the group of UrlDownloadToFileA, UrlDownloadToFileW, UrlDownloadToCacheFileA, and UrlDownloadToCacheFileW.

13. The computer of claim 11 , wherein the code is downloaded over a network.

14. The computer of claim 11 , wherein the remedial action comprises returning an error code to the code that called the hooked downloading function.

15. The computer of claim 11 , wherein the remedial action comprises displaying an alert.

Assignments (4)
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
CHANGE OF NAME Recorded Jun 18, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 053306/0878 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →