发明名称 SYSTEM AND METHOD FOR KERNEL ROOTKIT PROTECTION IN HYPERVISOR ENVIRONMENT
摘要 PROBLEM TO BE SOLVED: To provide a system and method for kernel rootkit protection in a hypervisor environment.SOLUTION: A system includes; a module for creating a soft whitelist 38 having entries corresponding to each guest kernel page 30 in a guest operating system 18 in a hypervisor environment; a module 40 for generating a page fault when an access attempt is made to a guest kernel page 30; a module for fixing the page fault to allow access and execution if the guest kernel page 30 corresponds to one of the entries in the soft whitelist 38; and a module for denying execution if the guest kernel page 30 does not correspond to any of the entries in the soft whitelist.SELECTED DRAWING: Figure 1
申请公布号 JP2016129071(A) 申请公布日期 2016.07.14
申请号 JP20160047660 申请日期 2016.03.10
申请人 MCAFEE INC 发明人 AMIT DANG;PREET MOHINDER;VIVEK SRIVASTAVA
分类号 G06F21/55;G06F9/46 主分类号 G06F21/55
代理机构 代理人
主权项
地址