Invention Grant
US09037823B2 Protecting IAT/EAT hooks from rootkit attacks using new CPU assists
有权
使用新的CPU协助来保护IAT / EAT钩子免受rootkit攻击
- Patent Title: Protecting IAT/EAT hooks from rootkit attacks using new CPU assists
- Patent Title (中): 使用新的CPU协助来保护IAT / EAT钩子免受rootkit攻击
-
Application No.: US13615928Application Date: 2012-09-14
-
Publication No.: US09037823B2Publication Date: 2015-05-19
- Inventor: Harshawardhan Vipat , Ravi L. Sahita
- Applicant: Harshawardhan Vipat , Ravi L. Sahita
- Applicant Address: US CA Santa Clara
- Assignee: Intel Corporation
- Current Assignee: Intel Corporation
- Current Assignee Address: US CA Santa Clara
- Agency: Grossman, Tucker, Perreault & Pfleger, PLLC
- Main IPC: G06F21/52
- IPC: G06F21/52 ; G06F21/62

Abstract:
The present disclosure provides systems and methods for hardware-enforced protection from malicious software. A device may include at least a security validator module and a security initiator module. A call from a process requesting access to information stored in the device may be redirected to the security initiator module, which may cause the device to change from an unsecured view to a secured view. In the secured view the security validator module may determine whether the call came from malicious software. If the call is determined to be valid, then access to the stored information may be permitted. If the call is determined to be invalid (e.g., from malware), the security software may cause the device to return to the unsecured view without allowing the stored information to be accessed, and may take further measures to identify and/or eliminate process code associated with the process that made the invalid call.
Public/Granted literature
- US20140082751A1 PROTECTING IAT/EAT HOOKS FROM ROOTKIT ATTACKS USING NEW CPU ASSISTS Public/Granted day:2014-03-20
Information query