发明名称 Detection of SYSENTER/SYSCALL hijacking
摘要 Techniques are disclosed for detecting manipulations of user-kernel transition registers (such as the SYSENTER/SYSCALL critical registers of Intel/AMD processors, respectively), and other such registers. In one embodiment, a register monitor agent is deployed at system boot-up, and continues monitoring target registers for manipulation during system use. If a manipulation is detected, then exclusions are checked to see if that manipulation is legitimate (e.g., caused by a trusted source). If not a legitimate manipulation, then reporting and/or corrective action can be taken. The techniques can be used in real-time and in any number of behavior blocking, antivirus, and/or intrusion prevention applications.
申请公布号 US7617534(B1) 申请公布日期 2009.11.10
申请号 US20050213289 申请日期 2005.08.26
申请人 SYMANTEC CORPORATION 发明人 SZOR PETER;FERRIE PETER;CONOVER MATTHEW
分类号 G06F12/14;G06F11/00 主分类号 G06F12/14
代理机构 代理人
主权项
地址