IP Library Granted Patent US 7,484,239
Granted Patent B1
US 7,484,239 · App. 11/000,817 · Granted Jan 27, 2009

Detecting heap and stack execution in the operating system using regions

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,484,239
App. No.
11/000,817
Granted
Jan 27, 2009
Kind
B1
Abstract

A call to a critical operating system function is stalled. The pregion and pregion type associated with the location of a call module originating the call is determined. In one embodiment, when the pregion type is either a stack or a heap pregion type, protective action is taken, such as terminating the call, otherwise the call is released. In another embodiment, when the pregion type is either a text or shared memory pregion type, the call is released, otherwise protective action is taken.

Claims (72)

1. A method comprising:

hooking at least one critical operating system function;

stalling a call to said at least one critical operating system function, said call originating from a call module at a location in a virtual address space allocated to a process;

determining a pregion associated with said location; and

determining a pregion type of said pregion.

2. The method of claim 1 , further comprising:

determining whether said pregion type is one of a stack pregion type and a heap pregion type;

wherein when said pregion type is one of said stack pregion type and said heap pregion type, taking protective action; and

wherein when said pregion type is not one of said stack pregion type and said heap pregion type, releasing said call.

3. The method of claim 1 , further comprising:

determining whether said pregion type is a text pregion type;

wherein when said pregion type is said text pregion type, releasing said call;

wherein when said pregion type is not said text pregion type, determining whether said pregion type is a shared memory pregion type;

wherein when said pregion type is said shared memory pregion type, releasing said call; and

wherein when said pregion type is not said shared memory pregion type, taking protective action.

4. A method comprising:

stalling a call to an operating system function, said call originating from a call module at a location in a virtual address space allocated to a process;

determining a virtual address of said call module;

determining a virtual address space of said process;

determining a pregion associated with said virtual address;

determining a pregion type of said pregion;

determining whether said pregion type is one of a stack and a heap pregion type; and

wherein when said pregion type is one of said stack pregion type and said heap pregion type, taking protective action.

5. The method of claim 4 , further comprising:

wherein when said pregion type is not one of said stack pregion type and said heap pregion type, releasing said call.

6. The method of claim 4 , further comprising:

wherein said operating system function is a critical operating system function, and

further wherein said call is a critical operating system function call.

7. The method of claim 4 , further comprising:

wherein said operating system function is a function which when executed spawns another process.

8. The method of claim 4 , further comprising:

hooking said operating system function.

9. The method of claim 4 , further comprising:

providing a notification.

10. A method comprising:

stalling a call to an operating system function, said call originating from a call module of a process;

determining a virtual address of said call module;

determining a virtual address space of said process;

determining a pregion associated with said virtual address;

determining a pregion type of said pregion;

determining whether said pregion type is a text pregion type;

wherein when said pregion type is not said text pregion type, determining whether said pregion type is a shared memory pregion type; and

wherein when said pregion type is not said shared memory pregion type, taking protective action.

11. The method of claim 10 , further comprising:

wherein when said pregion type is said text pregion type, releasing said call.

12. The method of claim 10 , further comprising:

wherein when said pregion type is said shared memory pregion type, releasing said call.

13. The method of claim 10 , further comprising:

wherein said operating system function is a critical operating system function, and

further wherein said call is a critical operating system function call.

14. The method of claim 10 , further comprising:

wherein said operating system function is a function which when executed spawns another process.

15. The method of claim 10 , further comprising:

hooking said operating system function.

16. The method of claim 10 , further comprising:

providing a notification.

17. A computer-program product comprising a computer readable storage medium containing computer program code comprising:

means for stalling a call to at least one critical operating system function, said call originating from a call module at a location in a virtual address space allocated to a process;

means for determining a pregion associated with said location; and

means for determining a pregion type of said pregion.

18. The computer-program product of claim 17 , further comprising:

means for determining whether said pregion type is one of a stack and a heap pregion type;

wherein when said pregion type is one of said stack pregion type and said heap pregion type, means for taking protective action; and

wherein when said pregion type is not one of said stack pregion type and said heap pregion type, means for releasing said call.

19. The computer-program product of claim 17 , further comprising:

means for determining whether said pregion type is a text pregion type;

wherein when said pregion type is said text pregion type, means for releasing said call;

wherein when said pregion type is not said text pregion type, means for determining whether said pregion type is a shared memory pregion type;

wherein when said pregion type is said shared memory pregion type, means for releasing said call; and

wherein when said pregion type is not said shared memory pregion type, means for taking protective action.

20. The computer-program product of claim 17 , further comprising:

means for hooking said at least one critical operating system function.

Assignments (6)
CHANGE OF NAME Recorded May 18, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 063697/0493 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Mar 5, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 052109/0186 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2004
From: TESTER, JONATHAN; VERMA, SUNITA
To: SYMANTEC CORPORATION
Reel/Frame 016053/0727 →