DETECTING AND PREVENTING EXECUTION OF SOFTWARE EXPLOITS

Patent №

US 10,284,591

Granted

2019-05-07

Filed 2015

Owner

WEBROOT INC.

Lab

AI components

1

hardware

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

14606604

In non-limiting examples, anti-exploit systems and methods described herein monitor a memory space of a process for execution of functions. Stack walk processing is executed upon invocation of one of the functions in the monitored memory space. During execution of the stack walk processing, at least one memory check is performed to detect suspicious behavior. An alert of suspicious behavior is triggered when the performing of the memory check detects at least one of: code execution attempted from non-executable memory, identification of an invalid base pointer, identification of an invalid stack return address, attempted execution of a return-oriented programming technique, the base pointer is outside a current thread stack, and a return address is detected as being inside a virtual memory area. If an alert of suspicious behavior is triggered, execution of a payload is prevented for the invoked function.

AI hardwareH04L 63/1441G06F 21/52G06F 21/554H04L 63/1408

AI classification

AI hardware1.00
Knowledge representation0.00
Evolutionary computation0.00
Natural language0.00
Machine learning0.00
Speech0.00
Vision0.00
Planning0.00

Ownership

WEBROOT INC.

assignment · 348230021

Assignors

GIULIANI, MARCO, BIZZARRI, MARCO, VOLTATTORNI, BENEDETTO, MAYR, JOHANNES

On an employer assignment, the assignors are typically the inventors.

© 2026 NYSGPT2525 LLC