Security method for detecting intrusions that exploit misinterpretation of supplied data
Patent №
US 8,819,822
Granted
2014-08-26
Filed 2006
Owner
VMWARE, INC.
Lab
—
AI components
3
nlp · planning · hardware
Assignment
Recorded
Dataset
AIPD
2023_r1 edition
Application
11395817
Mechanisms have been developed for securing computational systems against certain forms of attack. In particular, it has been discovered that, by scanning an input string for subsequences contained therein and configuring the computational system to generate a fault (or other triggered event) coincident with access to a memory location corresponding to one or more possible interpretations of data contained in the input string, it is possible to detect and/or interdict many forms of attack. For example, some realizations may scan for subsequences susceptible to interpretation as valid, canonical addresses, or as addresses in ranges that contain code, the stack, the heap, and/or system data structures such as the global offset table. Some realizations may scan for subsequences susceptible to interpretation as format strings or as machine code or code (source or otherwise) that could be executed in an execution environment (such as a Java™ virtual machine) or compiled for execution.
AI classification
Ownership
VMWARE, INC.
assignment · 177150408
Assignors
PIKE, GEOFFREY, LEAKE, EDWARD N.
On an employer assignment, the assignors are typically the inventors.