发明名称 METHOD OF INVOKING SYSTEM FUNCTIONS IN CONDITIONS OF USE OF AGENTS FOR PROTECTING OPERATING SYSTEM KERNEL
摘要 FIELD: information security.SUBSTANCE: invention relates to antivirus technologies, and more specifically to a method of creating handler system calls. According to one version, method of system function call, during which following steps are performed: loading hypervisor for interception of handler system calls. Modifying structure of operating system kernel, connected to system function call, said structure operating system kernel includes at least: a) a system call; b) system call table in which address of call is replaced with at least one system function call address on other function with maintaining original address system function call; intercepting system call handler call by hypervisor; calling another function at any replacement address in system call; calling system function on stored original address.EFFECT: technical result consists in a system function call in conditions of use of operating system kernel protection means.1 cl, 7 dwg
申请公布号 RU2585978(C2) 申请公布日期 2016.06.10
申请号 RU20140139202 申请日期 2014.09.30
申请人 ZAKRYTOE AKTSIONERNOE OBSHSHESTVO "LABORATORIYA KASPERSKOGO" 发明人 YUDIN MAKSIM VITALEVICH;TARASENKO ALEKSANDR SERGEEVICH;LEVCHENKO VYACHESLAV IVANOVICH;KUMAGIN IGOR YUREVICH
分类号 G06F9/06 主分类号 G06F9/06
代理机构 代理人
主权项
地址