发明授权
- 专利标题: Optimizing performance of integrity monitoring
- 专利标题(中): 优化完整性监控的性能
-
申请号: US12761952申请日: 2010-04-16
-
公开(公告)号: US08949797B2公开(公告)日: 2015-02-03
- 发明人: Najwa Aaraj , Mihai Christodorescu , Dimitrios Pendarakis , Reiner Sailer , Douglas L. Schales
- 申请人: Najwa Aaraj , Mihai Christodorescu , Dimitrios Pendarakis , Reiner Sailer , Douglas L. Schales
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 代理机构: Scully, Scott, Murphy & Presser, P.C.
- 代理商 Preston J. Young, Esq.
- 主分类号: G06F9/44
- IPC分类号: G06F9/44 ; G06F9/45 ; G06F21/56 ; G06F21/55
摘要:
A system, method and computer program product for verifying integrity of a running application program on a computing device. The method comprises: determining entry points into an application programs processing space that impact proper execution impact program integrity; mapping data elements reachable from the determined entry points into a memory space of a host system where the application to verify is running; run-time monitoring, in the memory space, potential modification of the data elements in a manner potentially breaching program integrity; and initiating a response to the potential modification. The run-time monitoring detects when a data transaction, e.g., a write event, reaches a malicious agent's entry point, a corresponding memory hook is triggered and control is passed to a security agent running outside the monitored system. This agent requests the values of the data elements, and determines if invariants that have been previously computed hold true or not under the set of retrieved data values.
公开/授权文献
- US20110258610A1 OPTIMIZING PERFORMANCE OF INTEGRITY MONITORING 公开/授权日:2011-10-20
信息查询