IP Library Granted Patent US 9,218,467
Granted Patent B2
US 9,218,467 · App. 13/905,122 · Granted Dec 22, 2015

Intra stack frame randomization for protecting applications against code injection attack

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,218,467
App. No.
13/905,122
Granted
Dec 22, 2015
Kind
B2
Abstract

A method of randomizing locations of variables in a stack includes: identifying a plurality of stack locations corresponding to a plurality of variables; shuffling the stack locations of the variables to produce shuffled stack locations; and updating the stack locations of the variables with the shuffled stack locations.

Claims (44)

1. A computer implemented method of randomizing locations of variables in a stack associated with a software application, prior to said randomizing locations, the stack including, in order from a bottom of the stack to a top of the stack, a return address for a function call, a local variable and an attackable buffer, the method comprising:

identifying, by one or more processors, a local function in the software application;

identifying, by the one or more processors, a plurality of stack locations of a plurality of variables in the identified local function;

identifying, by the one or more processors, references to each of the plurality of variables in the identified local function;

shuffling, by an executable loader that loads the software application, the stack locations of the variables to produce shuffled stack locations of the variables, each time that the software application is loaded into a memory, wherein each execution of the software program results in a different shuffling, wherein said shuffled stack locations of the variables changes a critical stack distance between the return address for the local function and the attackable buffer, and wherein the critical stack distance is a sum of a size of the local variable and a size of the attackable buffer; and

updating the stack locations of the variables with the shuffled stack locations.

2. The method of claim 1 , wherein the identifying the stack locations comprises identifying variables in object code, and

wherein the updating the stack locations of the variables comprises updating the object code with the shuffled stack locations.

3. The method of claim 1 , wherein the identifying the stack locations comprises identifying variables in binary code, and

wherein the updating the stack locations of the variables comprises updating the binary code with the shuffled stack locations.

4. The method of claim 1 , wherein the identifying the stack locations comprises identifying variables in executable code loaded into memory, and

wherein the updating the stack locations of the variables comprises updating the executable code loaded into memory with the shuffled stack locations.

5. The method of claim 4 , wherein the shuffling the stack locations of the variables to produce shuffled stack locations and the updating the stack locations of the variables with the shuffled stack locations occur prior to execution of the executable code.

6. The method of claim 4 , wherein the shuffling the stack locations of the variables to produce shuffled stack locations and the updating the stack locations of the variables with the shuffled stack locations occur during execution of the executable code.

7. A non-transitory computer readable medium embodying program instructions for execution by a data processing apparatus for randomizing locations of variables in a stack associated with a software application, prior to said randomizing locations, the stack including, in order from a bottom of the stack to a top of the stack, a return address for a function call, a local variable and an attackable buffer, the program instructions adapting the data processing apparatus for:

identifying, by one or more processors, a local function in the software application;

identifying, by the one or more processors, a plurality of stack locations of a plurality of variables in the identified local function;

identifying, by the one or more processors, references to each of the plurality of variables in the identified local function;

shuffling, by an executable loader that loads the software application, the stack locations of the variables to produce shuffled stack locations of the variables, each time that the software application is loaded into a memory, wherein each execution of the software program results in a different shuffling, aid wherein said shuffled stack locations of the variables changes a critical stack distance between the return address for the local function and the attackable buffer, and wherein the critical stack distance is a sum of a size of the local variable and a size of the attackable buffer; and

updating the stack locations of the variables with the shuffled stack locations.

8. The non-transitory computer readable medium of claim 7 , wherein the identifying the stack locations comprises identifying variables in object code, and

wherein the updating the stack locations of the variables comprises updating the object code with the shuffled stack locations.

9. The non-transitory computer readable medium of claim 7 , wherein the identifying the stack locations comprises identifying variables in binary code, and

wherein the updating the stack locations of the variables comprises updating the binary code with the shuffled stack locations.

10. The non-transitory computer readable medium of claim 7 , wherein the identifying the stack locations comprises identifying variables in executable code loaded into memory, and

wherein the updating the stack locations of the variables comprises updating the executable code loaded into memory with the shuffled stack locations.

11. The non-transitory computer readable medium of claim 10 , wherein the shuffling the stack locations of the variables to produce shuffled stack locations and the updating the stack locations of the variables with the shuffled stack locations occur prior to execution of the executable code.

12. The non-transitory computer readable medium of claim 10 , wherein the shuffling the stack locations of the variables to produce shuffled stack locations and the updating the stack locations of the variables with the shuffled stack locations occur during execution of the executable code.

13. A computer system for randomizing locations of variables in a stack associated with a software application, prior to said randomizing locations, the stack including, in order from a bottom of the stack to a top of the stack, a return address for a function call, a local variable and an attackable buffer, comprising:

a processor; and

memory storing program instructions, the program instructions being configured to control the computer system to:

identify, by the processor, a local function in the software application;

identify, by the processor, a plurality of stack locations of a plurality of variables in the identified local function;

identify, by the processor, references to each of the plurality of variables in the identified local function;

shuffle, by an executable loader that loads the software application, the stack locations of the variables to produce shuffled stack locations of the variables, each time that the software application is loaded into the memory, wherein each execution of the software program results in a different shuffling, wherein said shuffled stack locations of the variables changes a critical stack distance between the return address for the local function and the attackable buffer, and wherein the critical stack distance is a sum of a size of the local variable and a size of the attackable buffer; and

update the stack locations of the variables with the shuffled stack locations.

14. The computer system of claim 13 , wherein the identifying the stack locations comprises identifying variables in object code, and

wherein the updating the stack locations of the variables comprises updating the object code with the shuffled stack locations.

15. The computer system of claim 13 , wherein the identifying the stack locations comprises identifying variables in binary code, and

wherein the updating the stack locations of the variables comprises updating the binary code with the shuffled stack locations.

16. The computer system of claim 13 , wherein the identifying the stack locations comprises identifying variables in executable code loaded into memory, and

wherein the updating the stack locations of the variables comprises updating the executable code loaded into memory with the shuffled stack locations.

17. The computer system of claim 16 , wherein the shuffling the stack locations of the variables to produce shuffled stack locations and the updating the stack locations of the variables with the shuffled stack locations occur prior to execution of the executable code.

18. The computer system of claim 16 , wherein the shuffling the stack locations of the variables to produce shuffled stack locations and the updating the stack locations of the variables with the shuffled stack locations occur during execution of the executable code.

Assignments (13)
CHANGE OF NAME Recorded Mar 21, 2025
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: EVERFOX HOLDINGS LLC
Reel/Frame 070585/0524 →
PARTIAL PATENT RELEASE AND REASSIGNMENT AT REEL/FRAME 055052/0302 Recorded Oct 3, 2023
From: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: FORCEPOINT FEDERAL HOLDINGS LLC (F/K/A FORCEPOINT LLC)
Reel/Frame 065103/0147 →
SECURITY INTEREST Recorded Sep 29, 2023
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 065086/0822 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0309 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: FORCEPOINT FEDERAL LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0460 →
CHANGE OF NAME Recorded Feb 16, 2016
From: RAYTHEON CYBER PRODUCTS, LLC
To: FORCEPOINT FEDERAL LLC
Reel/Frame 037821/0818 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
CHANGE OF NAME Recorded Jun 2, 2015
From: RAYTHEON CYBER PRODUCTS, INC.
To: RAYTHEON CYBER PRODUCTS, LLC
Reel/Frame 035806/0367 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2015
From: RAYTHEON BBN TECHNOLOGIES CORP.
To: RAYTHEON CYBER PRODUCTS, INC.
Reel/Frame 035794/0226 →
CONFIRMATORY LICENSE Recorded Jun 12, 2013
From: RAYTHEON BBN TECHNOLOGIES CORPORATION
To: AFRL/RIJ
Reel/Frame 030601/0462 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 31, 2013
From: MATTHEWS, DAVID; MARTZ, ROBERT
To: RAYTHEON BBN TECHNOLOGIES, CORP.
Reel/Frame 030519/0559 →