发明名称 SYSTEM AND METHOD FOR KERNEL ROOTKIT PROTECTION IN A HYPERVISOR ENVIRONMENT
摘要 <p>A system and method for rootkit protection in a hypervisor environment includes modules for creating a soft whitelist having entries corresponding to each guest kernel page of a guest operating system in a hypervisor environment, wherein each entry is a duplicate page of the corresponding guest kernel page, generating a page fault when a process attempts to access a guest kernel page, and redirecting the process to the corresponding duplicate page. If the page fault is a data page fault, the method includes fixing the page fault, and marking a page table entry corresponding to the guest kernel page as non-executable and writeable. If the page fault is an instruction page fault, the method includes marking a page table entry corresponding to the guest kernel page as read-only. Redirecting changing a machine page frame number in a shadow page table of the hypervisor to point to the corresponding duplicate page.</p>
申请公布号 EP2766844(A1) 申请公布日期 2014.08.20
申请号 EP20120839735 申请日期 2012.09.15
申请人 MCAFEE, INC. 发明人 DANG, AMIT;MOHINDER, PREET;SRIVASTAVA, VIVEK
分类号 G06F21/10;G06F9/455;G06F21/00 主分类号 G06F21/10
代理机构 代理人
主权项
地址