Systems and Methods for Providing a Computing Device Having a Secure Operating System Kernel
    1.
    发明申请
    Systems and Methods for Providing a Computing Device Having a Secure Operating System Kernel 审中-公开
    提供具有安全操作系统内核的计算设备的系统和方法

    公开(公告)号:US20120216281A1

    公开(公告)日:2012-08-23

    申请号:US13315531

    申请日:2011-12-09

    IPC分类号: G06F21/24

    摘要: A method and apparatus for resisting malicious code in a computing device. A software component corresponding to an operating system kernel is analyzed prior to executing the software component to detect the presence of one or more specific instructions such as malicious code, a change in mode permissions or instructions to modify or turn off security monitoring software, and taking a graduated action in response to the detection of one or more specific instructions. The graduated action taken is specified by a security policy (or policies) stored on the computing device. The analyzing may include off-line scanning of a particular code or portion of code for certain instructions, op codes, or patterns, and includes scanning in real-time as the kernel or kernel module is loading while the code being scanned is not yet executing (i.e., it is not yet “on-line”). Analysis of other code proceeds according to policies.

    摘要翻译: 一种用于在计算设备中抵抗恶意代码的方法和装置。 在执行软件组件之前分析对应于操作系统内核的软件组件以检测一个或多个特定指令的存在,例如恶意代码,模式许可的改变或修改或关闭安全监控软件的指令,以及采取 响应于检测到一个或多个特定指令的分级动作。 所采取的分级动作由存储在计算设备上的安全策略(或策略)指定。 分析可以包括用于某些指令,操作代码或模式的特定代码或代码部分的离线扫描,并且包括当正在扫描的代码尚未执行时内核或内核模块正在加载时实时扫描 (即,它还没有“在线”)。 根据政策对其他代码进行分析。