WO2012148080A3 - Dll 인젝션 기능을 구비한 컴퓨팅 장치 및 dll 인젝션 방법 - Google Patents

Dll 인젝션 기능을 구비한 컴퓨팅 장치 및 dll 인젝션 방법 Download PDF

Info

Publication number
WO2012148080A3
WO2012148080A3 PCT/KR2012/001775 KR2012001775W WO2012148080A3 WO 2012148080 A3 WO2012148080 A3 WO 2012148080A3 KR 2012001775 W KR2012001775 W KR 2012001775W WO 2012148080 A3 WO2012148080 A3 WO 2012148080A3
Authority
WO
WIPO (PCT)
Prior art keywords
target process
dll
dll injection
target
injection
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/KR2012/001775
Other languages
English (en)
French (fr)
Other versions
WO2012148080A2 (ko
Inventor
이종일
이남수
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Fasoo com Co Ltd
Original Assignee
Fasoo com Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Fasoo com Co Ltd filed Critical Fasoo com Co Ltd
Priority to EP12777809.0A priority Critical patent/EP2704004B1/en
Priority to JP2014508278A priority patent/JP2014518582A/ja
Priority to US14/113,249 priority patent/US8875165B2/en
Publication of WO2012148080A2 publication Critical patent/WO2012148080A2/ko
Publication of WO2012148080A3 publication Critical patent/WO2012148080A3/ko
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/44Arrangements for executing specific programs
    • G06F9/445Program loading or initiating
    • G06F9/44521Dynamic linking or loading; Link editing at or after load time, e.g. Java class loading
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/52Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow
    • G06F21/53Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow by executing in a restricted environment, e.g. sandbox or secure virtual machine
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/71Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
    • G06F21/74Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information operating in dual or compartmented mode, i.e. at least one secure mode
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/44Arrangements for executing specific programs
    • G06F9/451Execution arrangements for user interfaces

Landscapes

  • Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • Theoretical Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • Computer Security & Cryptography (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Hardware Design (AREA)
  • Mathematical Physics (AREA)
  • Human Computer Interaction (AREA)
  • Stored Programmes (AREA)

Abstract

DLL 인젝션 기능을 구비한 컴퓨팅 장치 및 DLL 인젝션 방법이 개시된다. 운영 체제로부터 사용자가 실행을 명령한 프로그램에 대응하는 대상 프로세스의 생성 여부가 통지되면, 인젝션 프로그램의 프로세스 생성모듈은 런처 프로세스를 실행하여 런처 프로세스의 자식 프로세스로서 상기 대상 프로세스를 생성하고, 대상 프로세스를 중지 모드로 설정한다. 코드 삽입모듈은 대상 프로세스의 프로세스 핸들을 이용하여 대상 프로세스가 적재된 메모리 영역을 할당받아 대상 프로세스에 인젝션하고자 하는 DLL 파일을 실행하는 코드를 삽입한다. 복원모듈은 대상 프로세스의 중지 모드를 해제하여 대상 프로세스가 실행되도록 한다. 본 발명에 따르면, 중지 모드로 생성된 대상 프로세스의 메모리 영역에 DLL 실행 코드를 삽입함으로써, 다른 DLL 인젝션 기법과 충돌하지 않고 안정적으로 DLL 인젝션을 수행할 수 있다.
PCT/KR2012/001775 2011-04-28 2012-03-12 Dll 인젝션 기능을 구비한 컴퓨팅 장치 및 dll 인젝션 방법 Ceased WO2012148080A2 (ko)

Priority Applications (3)

Application Number Priority Date Filing Date Title
EP12777809.0A EP2704004B1 (en) 2011-04-28 2012-03-12 Computing device having a dll injection function, and dll injection method
JP2014508278A JP2014518582A (ja) 2011-04-28 2012-03-12 Dllインジェクション機能を持つコンピュータ装置及びdllインジェクション方法
US14/113,249 US8875165B2 (en) 2011-04-28 2012-03-12 Computing device having a DLL injection function, and DLL injection method

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
KR1020110039901A KR101242127B1 (ko) 2011-04-28 2011-04-28 Dll 인젝션 기능을 구비한 컴퓨팅 장치 및 dll 인젝션 방법
KR10-2011-0039901 2011-04-28

Publications (2)

Publication Number Publication Date
WO2012148080A2 WO2012148080A2 (ko) 2012-11-01
WO2012148080A3 true WO2012148080A3 (ko) 2013-01-03

Family

ID=47072842

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/KR2012/001775 Ceased WO2012148080A2 (ko) 2011-04-28 2012-03-12 Dll 인젝션 기능을 구비한 컴퓨팅 장치 및 dll 인젝션 방법

Country Status (5)

Country Link
US (1) US8875165B2 (ko)
EP (1) EP2704004B1 (ko)
JP (1) JP2014518582A (ko)
KR (1) KR101242127B1 (ko)
WO (1) WO2012148080A2 (ko)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106095482A (zh) * 2016-05-31 2016-11-09 宇龙计算机通信科技(深圳)有限公司 应用程序的冻结方法及装置

Families Citing this family (14)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109684824B (zh) * 2014-12-29 2021-09-03 北京奇虎科技有限公司 进程的权限配置方法及装置
US10083296B2 (en) * 2015-06-27 2018-09-25 Mcafee, Llc Detection of malicious thread suspension
US10235161B2 (en) * 2017-02-06 2019-03-19 American Megatrends, Inc. Techniques of adding security patches to embedded systems
JP6957311B2 (ja) * 2017-10-25 2021-11-02 システムインテリジェント株式会社 情報漏洩防止装置、及び情報漏洩防止プログラム
US10747874B2 (en) * 2018-05-22 2020-08-18 NortonLifeLock, Inc. Systems and methods for controlling an application launch based on a security policy
KR102146882B1 (ko) 2018-11-12 2020-08-21 주식회사 안랩 메시지 모니터링 장치 및 방법
CN111198723B (zh) * 2018-11-19 2023-03-07 深圳市优必选科技有限公司 一种进程注入方法、终端设备及计算机可读存储介质
KR101958933B1 (ko) * 2018-12-18 2019-03-18 주식회사 웨어밸리 소켓 인젝션을 통한 데이터베이스 내의 정보 수집 방법 및 장치
US11170126B2 (en) 2019-01-03 2021-11-09 Citrix Systems, Inc. Policy based notification protection service in workspace
US11307910B2 (en) * 2019-06-10 2022-04-19 Citrix Systems, Inc. Notification tagging for a workspace or application
CN111338922B (zh) * 2020-03-02 2023-04-11 武汉思普崚技术有限公司 Dll失效的检测方法及装置
CN111475229B (zh) * 2020-04-09 2021-01-15 广州锦行网络科技有限公司 一种Windows平台下的dll注入方法及系统
US11681520B2 (en) 2021-04-20 2023-06-20 International Business Machines Corporation Software upgrading using dynamic link library injection
CN116932046B (zh) * 2022-04-12 2026-04-21 数篷信息技术(深圳)有限公司 进程入口的内核注入方法、代码执行方法、系统及设备

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6141698A (en) * 1997-01-29 2000-10-31 Network Commerce Inc. Method and system for injecting new code into existing application code
US6463583B1 (en) * 1999-04-08 2002-10-08 Novadigm, Inc. Dynamic injection of execution logic into main dynamic link library function of the original kernel of a windowed operating system
JP2011013955A (ja) * 2009-07-02 2011-01-20 Hitachi Systems & Services Ltd メディアチェック回避システム

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7039919B1 (en) * 1998-10-02 2006-05-02 Microsoft Corporation Tools and techniques for instrumenting interfaces of units of a software program
US8769268B2 (en) * 2007-07-20 2014-07-01 Check Point Software Technologies, Inc. System and methods providing secure workspace sessions
US8578483B2 (en) * 2008-07-31 2013-11-05 Carnegie Mellon University Systems and methods for preventing unauthorized modification of an operating system
US20120167057A1 (en) * 2010-12-22 2012-06-28 Microsoft Corporation Dynamic instrumentation of software code

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6141698A (en) * 1997-01-29 2000-10-31 Network Commerce Inc. Method and system for injecting new code into existing application code
US6463583B1 (en) * 1999-04-08 2002-10-08 Novadigm, Inc. Dynamic injection of execution logic into main dynamic link library function of the original kernel of a windowed operating system
JP2011013955A (ja) * 2009-07-02 2011-01-20 Hitachi Systems & Services Ltd メディアチェック回避システム

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP2704004A4 *

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106095482A (zh) * 2016-05-31 2016-11-09 宇龙计算机通信科技(深圳)有限公司 应用程序的冻结方法及装置

Also Published As

Publication number Publication date
US20140047461A1 (en) 2014-02-13
KR101242127B1 (ko) 2013-03-12
EP2704004A2 (en) 2014-03-05
US8875165B2 (en) 2014-10-28
EP2704004A4 (en) 2014-12-17
JP2014518582A (ja) 2014-07-31
KR20120121973A (ko) 2012-11-07
EP2704004B1 (en) 2016-02-03
WO2012148080A2 (ko) 2012-11-01

Similar Documents

Publication Publication Date Title
WO2012148080A3 (ko) Dll 인젝션 기능을 구비한 컴퓨팅 장치 및 dll 인젝션 방법
GB201216847D0 (en) Effective testing of authorization logic of web components which utilize claims-based authorization
WO2010068790A3 (en) Multi-threaded subgraph execution control in a graphical modeling environment
WO2013018019A3 (en) Advanced captcha using images in sequence
WO2012113547A3 (de) Verfahren zum betrieb einer mikroprozessoreinheit, insbesondere in einem mobilen endgerät
WO2013079380A3 (de) Hausgerät mit direkter erkennung des zu behandelnden gutes in bezug auf eine ausführung von erforderlichen behandlungschritten
WO2009088451A3 (en) Forced idle of a data processing system
GB202016053D0 (en) Injecting trap code in an execution path or a process executing a program to generate a trap address range to detect potential malicious code
EP2660668A3 (en) Systems and methods for controlling file execution for industrial control systems
MX2016014224A (es) Configuracion de flujos de trabajo en un dispositivo anfitrion que funciona en un sistema de control de procesos.
WO2014176310A3 (en) Controlling tasks performed by a computing system
WO2014146073A3 (en) Hardware simulation controller, system and method for functional verification
EP2555109A3 (en) Search utility program for software developers
GB2508553A (en) Protecting memory of a virtual guest
WO2009152511A3 (en) Control flow deviation detection for software security
EP2479673A3 (en) Software architecture for validating C++ programs using symbolic execution
PH12018501968B1 (en) Android-based pop-up prompt method and device
WO2013116073A9 (en) Method for reducing platform boot times by providing lazy input/output abstractions
WO2013192104A3 (en) Optimized execution of dynamic languages
MX2014015286A (es) Filtracion de interrupcion del programa en la ejecucion transaccional.
WO2011094006A3 (en) Providing sensory information based on intercepted events
IN2014DN07582A (ko)
PH12018500475A1 (en) Control device, control method, program, and control system
Bouyer et al. Robust reachability in timed automata and games: A game-based approach
WO2014033639A3 (en) Introspection of software program components and conditional generation of memory dump

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 12777809

Country of ref document: EP

Kind code of ref document: A2

WWE Wipo information: entry into national phase

Ref document number: 14113249

Country of ref document: US

ENP Entry into the national phase

Ref document number: 2014508278

Country of ref document: JP

Kind code of ref document: A

NENP Non-entry into the national phase

Ref country code: DE

WWE Wipo information: entry into national phase

Ref document number: 2012777809

Country of ref document: EP