发明申请
- 专利标题: AUTHENTICATION OF BINARIES IN MEMORY WITH PROXY CODE EXECUTION
- 专利标题(中): 使用代码执行的存储器中的二进制验证
-
申请号: US12163792申请日: 2008-06-27
-
公开(公告)号: US20090327711A1公开(公告)日: 2009-12-31
- 发明人: Aaron Goldsmid , Ping Xie , Scott Miller , Nir Ben Zvi , Nathan Jeffrey Ide , Manoj R. Mehta
- 申请人: Aaron Goldsmid , Ping Xie , Scott Miller , Nir Ben Zvi , Nathan Jeffrey Ide , Manoj R. Mehta
- 申请人地址: US WA Redmond
- 专利权人: Microsoft Corporation
- 当前专利权人: Microsoft Corporation
- 当前专利权人地址: US WA Redmond
- 主分类号: H04L9/28
- IPC分类号: H04L9/28 ; H04L9/00
摘要:
Presented is an anti-tampering method that validates and protects specific sections of a binary file. In one embodiment, this method permits a proxy engine to execute (via emulation by a virtual machine) the protected code on behalf of the binary in kernel mode upon successful completion of an integrity check. The integrity check can optionally check only the specific parts of code that the developer wishes to validate. The integrity check can cross binary boundaries. Moreover, the integrity check can be done on a hard drive or in memory. Furthermore, since the encrypted code is executed by the proxy engine in kernel mode, hackers are further deterred from modifying the code. Additionally, a method of creating a protected binary file is described herein.
公开/授权文献
信息查询