IP Library Granted Patent US 8,239,940
Granted Patent B2
US 8,239,940 · App. 12/537,893 · Granted Aug 7, 2012

Functional patching/hooking detection and prevention

Assignee: Trusteer Ltd.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,239,940
App. No.
12/537,893
Granted
Aug 7, 2012
Kind
B2
Abstract

A method for preventing malicious attacks on software, using the patching method, includes providing a database of legitimate and known patches, the database contains characteristic code paths of said legitimate patches. The method also includes detecting whether a patch is malicious by inspecting one or more characteristic paths of the patch and matching one or more code paths against the database of legitimate and known patches. An activity needed to prevent the malicious patch from performing undesired activities is then performed.

Claims (15)

1. A method for preventing malicious attacks on software using a patching method, comprising the steps of:

a) providing a database of legitimate and known patches, which database contains characteristic code paths of said legitimate patches;

b) detecting whether a first inspected patch is malicious by inspecting one or more characteristic code paths of said first inspected patch and matching said one or more characteristic code paths of said first inspected patch against said database of legitimate and known patches;

c) if a mismatch is found, determining whether said first inspected patch is a malicious patch and performing an activity needed to prevent said malicious patch from performing undesired activities by correcting or removing said malicious patch;

d) obtaining information from said database regarding where to search for a next inspected patch; and

e) repeating steps a) to d) until no match is found in said database.

2. A method according to claim 1 , wherein performing an activity needed to prevent said malicious patch from performing undesired activities comprises making changes to said malicious patch to prevent said malicious patch from performing undesired activities, or deleting said malicious patch.

3. A method according to claim 1 , wherein the characteristic code path inspected includes a pointer to a function in an Export Address Table (EAT).

4. A method according to claim 1 , wherein the characteristic code path inspected includes a pointer to a function in an Import Address Table (IAT) of currently loaded modules.

5. A method according to claim 1 , wherein the characteristic code path inspected includes a code of a function.

6. A method according to claim 1 , comprising providing in the database also information regarding where to look for the next patch.

7. A method according to claim 1 , further comprising providing in the database information on how to represent the code being examined as a continuous code.

8. The method according to claim 1 , wherein the software is a browser.

9. A method according to claim 1 , wherein performing an activity needed to prevent said malicious patch from performing undesired activities comprises reporting the presence of the malicious patch to a receiving entity.

10. A method according to claim 9 , wherein said receiving entity is selected from one or more of a remote software agent, a local software agent, or a user.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2017
From: TRUSTEER, LTD.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 041060/0411 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2009
From: KLEIN, AMIT; IZMERLY, OLEG; REGEV, SHMUEL; BEN-HAIM, ELDAN
To: TRUSTEER LTD.
Reel/Frame 023087/0055 →
Continuity (2)
Provisional Application 61140857 · Dec 25, 2008
Related Publication 20100169969A1 · Jul 1, 2010