Invention Grant
- Patent Title: Method of detecting malware in an operating system kernel
- Patent Title (中): 在操作系统内核中检测恶意软件的方法
-
Application No.: US14391763Application Date: 2013-03-27
-
Publication No.: US09177149B2Publication Date: 2015-11-03
- Inventor: Konstantin Dmitrievich Olshanov , Evgeny Petrovich Tumoyan , Sergei Nikolaevich Cherementsev
- Applicant: Joint Stock Company ″Info TeCS″
- Applicant Address: RU Moscow
- Assignee: Joint Stock Company “InfoTeCS”
- Current Assignee: Joint Stock Company “InfoTeCS”
- Current Assignee Address: RU Moscow
- Agency: Honigman Miller Schwartz and Cohn LLP
- Priority: RU2012113963 20120411
- International Application: PCT/RU2013/000249 WO 20130327
- International Announcement: WO2013/154459 WO 20131017
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F21/56 ; G06F21/55

Abstract:
The present invention relates to means for detecting malware. The method is realized on a computer with an operating system (OS) installed thereon, and comprises a step in which a point of interrupt is established when a system call is made by a user application requesting the transfer of control via an address in the kernel of the loaded OS. Next, the data structure of the loaded OS is checked. As this check is carried out, the address of the command in the random-access memory of the computer, by means of which command control will be transferred during the system call, is determined and the addresses of the commands to be executed during the system call are checked to see if they belong to the normal range of addresses of the OS kernel and OS kernel modules in the random-access memory. The presence of malware is then detected in the event that a command address does not belong to the normal range of addresses. The proposed method includes a dynamic check of the execution of the OS kernel code in order to detect the illegal interception and alteration of the code in the kernel and in the kernel modules (drivers) that are to be loaded. The proposed method enables the detection of both known and previously unregistered malware in an OS kernel and in OS kernel modules that are to be loaded.
Public/Granted literature
- US20150096028A1 Method of Detecting Malware in an Operating System Kernel Public/Granted day:2015-04-02
Information query