Invention Grant
- Patent Title: System and method for using snapshots for rootkit detection
- Patent Title (中): 使用快照进行rootkit检测的系统和方法
-
Application No.: US12954454Application Date: 2010-11-24
-
Publication No.: US08856927B1Publication Date: 2014-10-07
- Inventor: Serguei M. Beloussov , Maxim V. Lyadvinsky
- Applicant: Serguei M. Beloussov , Maxim V. Lyadvinsky
- Applicant Address: CH Schaffhausen
- Assignee: Acronis International GmbH
- Current Assignee: Acronis International GmbH
- Current Assignee Address: CH Schaffhausen
- Agency: Fish & Richardson P.C.
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/56

Abstract:
A system, method and computer program product for identifying malicious code running on a computer, including an operating system running on the computer with a data storage device; and a trusted software component running simultaneously with the operating system. An online snapshot process of a current state of the data storage device copies data blocks from the storage device to intermediate storage. Processes running under the control of the operating system have access to the data storage device. A scanning procedure runs under control of the trusted software component that has access to data representing the snapshot of the data storage device from the trusted software component. The scanning procedure analyzes the snapshot of the data storage device for the malicious code, and, in response to a “write” directed to a data block in the snapshot area of the storage device, that data block is written to the intermediate storage.
Information query