发明申请
US20120216281A1 Systems and Methods for Providing a Computing Device Having a Secure Operating System Kernel
审中-公开
提供具有安全操作系统内核的计算设备的系统和方法
- 专利标题: Systems and Methods for Providing a Computing Device Having a Secure Operating System Kernel
- 专利标题(中): 提供具有安全操作系统内核的计算设备的系统和方法
-
申请号: US13315531申请日: 2011-12-09
-
公开(公告)号: US20120216281A1公开(公告)日: 2012-08-23
- 发明人: Eric Ridvan Uner , Benjamin James Leslie , Joshua Scott Matthews , Changhua Chen , Thomas Smigelski , Anthony Kobrinetz
- 申请人: Eric Ridvan Uner , Benjamin James Leslie , Joshua Scott Matthews , Changhua Chen , Thomas Smigelski , Anthony Kobrinetz
- 申请人地址: US IL Bloomindale
- 专利权人: PCTEL Secure LLC
- 当前专利权人: PCTEL Secure LLC
- 当前专利权人地址: US IL Bloomindale
- 主分类号: G06F21/24
- IPC分类号: G06F21/24
摘要:
A method and apparatus for resisting malicious code in a computing device. A software component corresponding to an operating system kernel is analyzed prior to executing the software component to detect the presence of one or more specific instructions such as malicious code, a change in mode permissions or instructions to modify or turn off security monitoring software, and taking a graduated action in response to the detection of one or more specific instructions. The graduated action taken is specified by a security policy (or policies) stored on the computing device. The analyzing may include off-line scanning of a particular code or portion of code for certain instructions, op codes, or patterns, and includes scanning in real-time as the kernel or kernel module is loading while the code being scanned is not yet executing (i.e., it is not yet “on-line”). Analysis of other code proceeds according to policies.
信息查询