MITIGATING MALICIOUS EXPLOITATION OF A VULNERABILITY IN A SOFTWARE APPLICATION BY SELECTIVELY TRAPPING EXECUTION ALONG A CODE PATH
Patent №
US 7,845,006
Granted
2010-11-30
Filed 2007
Owner
INTERNATIONAL BUSINESS MACHINES CORPORATION
Lab
AI components
3
kr · planning · hardware
Assignment
Recorded
Dataset
AIPD
2023_r1 edition
Application
11626089
A method of reducing the window of malicious exploitation between vulnerability publication and the installation of a software patch. One or more probe points are inserted into a code path in an application (or operating system if applicable) that contains one or more vulnerabilities (or coding errors). The probe points mark locations of the security vulnerabilities utilizing software interrupts to enable the original code base of the code path to remain unmodified. A probe handler utility subsequently monitors the execution of the code path and generates an alert if the execution reaches a probe point in the code path, thus indicating whether the application exhibits a particular vulnerability. The probe handler selectively performs one of multiple customizable corrective actions, thereby securing the application until an applicable software patch can be installed.
AI classification
Ownership
INTERNATIONAL BUSINESS MACHINES CORPORATION
assignment · 188630910
Assignors
AKULAVENKATAVARA, PRASADARAO, GIROUARD, JANICE M, RATLIFF, EMILY J
On an employer assignment, the assignors are typically the inventors.