发明名称 Method and apparatus to detect kernel mode rootkit events through virtualization traps
摘要 Detecting a rootkit in a computing system may be achieved by detecting, by a virtual machine monitor, a virtualization trap occurring as a result of an action by a rootkit executing in a computing system; and analyzing the virtualization trap to detect the presence of the rootkit in the computing system. Action may then be taken to block the rootkit activity to safeguard the computing system.
申请公布号 US7845009(B2) 申请公布日期 2010.11.30
申请号 US20060435463 申请日期 2006.05.16
申请人 INTEL CORPORATION 发明人 GROBMAN STEVEN
分类号 G06F21/22;G06F9/445;G06F11/30 主分类号 G06F21/22
代理机构 代理人
主权项
地址