发明名称 |
SYSTEM AND METHOD FOR KERNEL ROOTKIT PROTECTION IN HYPERVISOR ENVIRONMENT |
摘要 |
PROBLEM TO BE SOLVED: To provide a system and method for kernel rootkit protection in a hypervisor environment.SOLUTION: A system includes; a module for creating a soft whitelist 38 having entries corresponding to each guest kernel page 30 in a guest operating system 18 in a hypervisor environment; a module 40 for generating a page fault when an access attempt is made to a guest kernel page 30; a module for fixing the page fault to allow access and execution if the guest kernel page 30 corresponds to one of the entries in the soft whitelist 38; and a module for denying execution if the guest kernel page 30 does not correspond to any of the entries in the soft whitelist.SELECTED DRAWING: Figure 1 |
申请公布号 |
JP2016129071(A) |
申请公布日期 |
2016.07.14 |
申请号 |
JP20160047660 |
申请日期 |
2016.03.10 |
申请人 |
MCAFEE INC |
发明人 |
AMIT DANG;PREET MOHINDER;VIVEK SRIVASTAVA |
分类号 |
G06F21/55;G06F9/46 |
主分类号 |
G06F21/55 |
代理机构 |
|
代理人 |
|
主权项 |
|
地址 |
|