- 专利标题: Methods to impede common file/process hiding techniques
-
申请号: US15899666申请日: 2018-02-20
-
公开(公告)号: US10185838B1公开(公告)日: 2019-01-22
- 发明人: Nathan Evans , Azzedine Benameur , Yun Shen
- 申请人: SYMANTEC CORPORATION
- 申请人地址: US CA Mountain View
- 专利权人: SYMANTEC CORPORATION
- 当前专利权人: SYMANTEC CORPORATION
- 当前专利权人地址: US CA Mountain View
- 代理机构: Maschoff Brennan
- 主分类号: G06F21/62
- IPC分类号: G06F21/62 ; H04L29/06
摘要:
A processor-based method to defeat file and process hiding techniques in a computing device is provided. The method includes generating one of a path permutation, a symlink, or an address, for a path to open or obtain status of a tool or function in a library in a mobile computing device and making an open or status call for the tool or function, using the one of the path permutation, symlink or address. The method includes avoiding a pattern match and blocking, by an injected library, of the open or status call, the avoiding being a result of making the open or status call using the path permutation, symlink or address.
信息查询