- Patent Title: Systems and methods for active operating system kernel protection
-
Application No.: US14942184Application Date: 2015-11-16
-
Publication No.: US09639698B2Publication Date: 2017-05-02
- Inventor: Maxim V. Yudin , Alexander S. Tarasenko , Vyacheslav I. Levchenko , Igor Y. Kumagin
- Applicant: AO Kaspersky Lab
- Applicant Address: RU Moscow
- Assignee: AO KASPERSKY LAB
- Current Assignee: AO KASPERSKY LAB
- Current Assignee Address: RU Moscow
- Agency: Patterson Thuente Pedersen P.A.
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F9/455 ; G06F21/53

Abstract:
Systems and methods for intercepting computing device system calls for a computing device including a kernel having a system call table. A hypervisor is executed on the computing device, the hypervisor configured to control at least one of the computing device processor registers. At least one modified kernel structure is created, the modified kernel structure including a modified system call table. A memory address of an original system call handler is determined, the original system call handler configured to receive kernel operation commands. A size of a loaded image of the original system call handler is determined. A copy of the original system call handler as a second system call handler is created, and the second system call handler intercepts a computing device system call.
Public/Granted literature
- US20160210456A1 SYSTEMS AND METHODS FOR ACTIVE OPERATING SYSTEM KERNEL PROTECTION Public/Granted day:2016-07-21
Information query