Invention Grant
US08417945B2 Detection and reporting of virtualization malware in computer processor environments
有权
在计算机处理器环境中检测和报告虚拟化恶意软件
- Patent Title: Detection and reporting of virtualization malware in computer processor environments
- Patent Title (中): 在计算机处理器环境中检测和报告虚拟化恶意软件
-
Application No.: US12165155Application Date: 2008-06-30
-
Publication No.: US08417945B2Publication Date: 2013-04-09
- Inventor: Hormuzd M. Khosravi , David Durham
- Applicant: Hormuzd M. Khosravi , David Durham
- Applicant Address: US CA Santa Clara
- Assignee: Intel Corporation
- Current Assignee: Intel Corporation
- Current Assignee Address: US CA Santa Clara
- Agency: Garrett IP, LLC
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Methods and systems to detect virtualization of computer system resources, such as by malware, include methods and systems to evaluate information corresponding to a computer processor operating environment, outside of or secure from the operating environment, which may include one or more of a system management mode of operation and a management controller system. Information may include processor register values. Information may be obtained from within the operating environment, such as with a host application running within the operating environment. Information may be obtained outside of the operating environment, such as from a system state map. Information obtained from within the operating environment may be compared to corresponding information obtained outside of the operating environment. Direct memory address (DMA) translation information may be used to determine whether an operating environment is remapping DMA accesses. Page tables, interrupt tables, and segmentation tables may be used to reconstruct a view of linear memory corresponding to the operating environment, which may be scanned for malware or authorized code and data.
Public/Granted literature
- US20090328042A1 DETECTION AND REPORTING OF VIRTUALIZATION MALWARE IN COMPUTER PROCESSOR ENVIRONMENTS Public/Granted day:2009-12-31
Information query