Invention Grant
- Patent Title: Optimizing performance of integrity monitoring
- Patent Title (中): 优化完整性监控的性能
-
Application No.: US12761952Application Date: 2010-04-16
-
Publication No.: US08949797B2Publication Date: 2015-02-03
- Inventor: Najwa Aaraj , Mihai Christodorescu , Dimitrios Pendarakis , Reiner Sailer , Douglas L. Schales
- Applicant: Najwa Aaraj , Mihai Christodorescu , Dimitrios Pendarakis , Reiner Sailer , Douglas L. Schales
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Scully, Scott, Murphy & Presser, P.C.
- Agent Preston J. Young, Esq.
- Main IPC: G06F9/44
- IPC: G06F9/44 ; G06F9/45 ; G06F21/56 ; G06F21/55

Abstract:
A system, method and computer program product for verifying integrity of a running application program on a computing device. The method comprises: determining entry points into an application programs processing space that impact proper execution impact program integrity; mapping data elements reachable from the determined entry points into a memory space of a host system where the application to verify is running; run-time monitoring, in the memory space, potential modification of the data elements in a manner potentially breaching program integrity; and initiating a response to the potential modification. The run-time monitoring detects when a data transaction, e.g., a write event, reaches a malicious agent's entry point, a corresponding memory hook is triggered and control is passed to a security agent running outside the monitored system. This agent requests the values of the data elements, and determines if invariants that have been previously computed hold true or not under the set of retrieved data values.
Public/Granted literature
- US20110258610A1 OPTIMIZING PERFORMANCE OF INTEGRITY MONITORING Public/Granted day:2011-10-20
Information query