IP Library › Granted Patent US 10,990,678
Granted Patent B2
US 10,990,678 · App. 16/044,509 · Granted Apr 27, 2021

Method to protect application running in a hostile environment

Inventors: Egemen Tas (North Bergen, NJ); Haibo Zhang (Beijing, CN)
G06F21/566G06F21/561G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,990,678
App. No.
16/044,509
Granted
Apr 27, 2021
Kind
B2
Abstract

There is provided a method to protect applications running in a hostile environment, including against trampoline based attacks which use dll injection and code modification. The method includes protecting an application when access is performed from injected dll, and protecting the application when access is performed from modified codes.

Claims (14)

1. A method to defend against trampoline based attacks which use dynamic link library (dll) injection and code modification comprising:

protecting an application when access is performed from injected dll, and protecting said application when access is performed from modified codes, where said application is protected when said access is performed from said injected dll, by

intercepting open process requests by setting up API hooks in all processes,

obtaining return address of the open process call if an open process request targets protected application,

obtaining start address of the module from where said open process call originates,

obtaining module file path and determine if said module file path is a legal dll or executable module by checking signature, scanning with antivirus engine or querying in a cloud verdict service.

2. A method to defend against trampoline based attacks which use dynamic link library (dll) injection and code modification comprising:

protecting an application when access is performed from injected dll, and protecting said application when access is performed from modified codes, where the application is protected when said access is performed from said modified codes, by

loading module file into memory as image file or helper image, which relocates instructions properly,

calculating offset of return address in calling module,

locating address of open process call in helper image and calling said address address-in-helper-image,

disassembling several instructions at said address-in-helper-image and instructions at return address,

comparing operation codes of said disassembled instructions, and

rejecting open process request if instructions are different, as meaning that codes of system process have been modified illegally.

Continuity (2)
Provisional Application 62537416 · Jul 26, 2017
Related Publication 20190114424A1 · Apr 18, 2019
Cited By (1)
US 12,346,430