Method and device for detecting return-oriented programming attack

A backhaul and application programming interface technology, applied in the field of network security, can solve problems such as non-support and security issues, and achieve the effect of avoiding ROP attacks and improving network security

Active Publication Date: 2015-01-07
ZHUHAI BAOQU TECH CO LTD
View PDF4 Cites 23 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

In this way, on the one hand, many early operating systems, such as early versions of msvcrt.dll, gdi32.dll, etc., do not support ASLR and support compilers, resulting in early operating systems that are easily exploited by attackers to successfully construct ROP attack codes are used to attack

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method and device for detecting return-oriented programming attack
  • Method and device for detecting return-oriented programming attack
  • Method and device for detecting return-oriented programming attack

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0023] The embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0024] It should be understood that the described embodiments are only some, but not all, embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0025] figure 1 This is a schematic flowchart of a method for detecting a backhaul-oriented programming attack according to an embodiment of the present invention. see figure 1 , the method includes:

[0026] Step 101, inject a preset application programming interface function monitoring program into the process of each application program to be monitored;

[0027] In this step, injecting the application programming interface function monitoring program into the process of the application program is to enable the...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The embodiment of the invention discloses a method and a device for detecting return-oriented programming attack. The method for detecting the return-oriented programming attack comprises injecting preset application programming interface (API) function monitoring programs into the process of every application program to be monitored; when the process of the application program to be monitored calls API functions inside a preset API function library, retarding the process of the application program to be monitored from calling the API functions; processing the calling-retarded API functions according to preset return-oriented programming (ROP) protecting strategies to determine whether calling the calling-retarded API functions is allowed. The method and device for detecting the return-oriented programming attack can effectively detect ROP attack and accordingly improve network security.

Description

technical field [0001] The present invention relates to a network security technology, and in particular, to a method and a device for detecting a return-oriented programming (ROP, Return-oriented Programming) attack. Background technique [0002] With the wide application of computer network technology, the Internet has gradually become the main way for malicious applications to attack users. Malicious applications disguise application files as other types of files and lure users to click and download. After the computer is successfully running, the attacker can use the installed malicious application to attack the vulnerabilities of the operating system and application software, for example, destroy the user's computer and steal the user's private information. Among them, a vulnerability refers to a flaw in the logic design of the operating system or application software or an error generated during writing. These flaws or errors can often be exploited by attackers and im...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
IPC IPC(8): G06F21/56
CPCG06F21/566G06F2221/033
Inventor 薛小昊刘桂峰姚辉
Owner ZHUHAI BAOQU TECH CO LTD
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products