METHOD AND SYSTEM FOR FILTERING COMMUNICATIONS TO PREVENT EXPLOITATION OF A SOFTWARE VULNERABILITY
Application 297/DEL/2005 published 2006-11-10, filed 2005-02-11
A method and system for protecting an application that implements a communication protocol against exploitation of a communication-based vulnerability is provided. A protection system provides a protection policy that specifies how to recognize messages that expose a specific vulnerability and specifies actions to take when the vulnerability is exposed. A protection policy specifies the sequence of messages and their payload characteristics that expose a vulnerability. The protection system may specify the sequences of messages using a message protocol state machine. A message protocol state machine of an application represents the states that the application transitions through as it receives various messages. The message protocol state machine of the protection policy may be a portion of the message protocol state machine of the application relating to the vulnerability. The protection system uses the message protocol state machine to track the states that lead up to the exposing of the vulnerability.
Applicant
1)MICROSOFT CORPORATION
:One Microsoft Way, Redmond, Washington 98052, United States of America U.S.A.
Inventor
1)ALF ZUGENMAIER 2)CHUANXIONG GUO 3)DANIEL R. SIMON 4)JASON GARMS 5)JIAHE HELEN WANG
International Info
Classification: G06F
Priority Information
60/547,131 U.S.A. 2004-02-24