TECHNOLOGIES FOR PREVENTING HOOK-SKIPPING ATTACKS USING PROCESSOR VIRTUALIZATION FEATURES
    5.
    发明申请
    TECHNOLOGIES FOR PREVENTING HOOK-SKIPPING ATTACKS USING PROCESSOR VIRTUALIZATION FEATURES 有权
    使用处理器虚拟化功能防止跳槽攻击的技术

    公开(公告)号:US20150379263A1

    公开(公告)日:2015-12-31

    申请号:US14318215

    申请日:2014-06-27

    IPC分类号: G06F21/56

    CPC分类号: G06F21/79 G06F21/62

    摘要: Technologies for monitoring system API calls include a computing device with hardware virtualization support. The computing device establishes a default memory view and a security memory view to define physical memory maps and permissions. The computing device executes an application in the default memory view and executes a default inline hook in response to a call to an API function. The default inline hook switches to the security memory view using hardware support without causing a virtual machine exit. The security inline hook calls a security callback function to validate the API function call in the security memory view. Hook-skipping attacks may be prevented by padding the default inline hook with no-operation instructions, by designating memory pages of the API function as non-executable in the default memory view, or by designating memory pages of the application as non-executable in the security memory view. Other embodiments are described and claimed.

    摘要翻译: 用于监视系统API调用的技术包括具有硬件虚拟化支持的计算设备。 计算设备建立默认内存视图和安全内存视图来定义物理内存映射和权限。 计算设备在默认存储器视图中执行应用程序,并响应于对API函数的调用执行默认内联钩子。 默认内联挂钩将使用硬件支持切换到安全内存视图,而不会导致虚拟机退出。 安全内联钩调用安全回调函数来验证安全内存视图中的API函数调用。 通过将默认内存视图中的不可执行的API函数的内存页指定为不可执行的内存页,或者通过将应用程序的内存页指定为不可执行的方式,可以通过使用无操作指令填充默认内联钩来防止跳钩攻击 安全内存视图。 描述和要求保护其他实施例。

    Endoscopic surgical instrument with deflectable and rotatable distal end
    6.
    发明授权
    Endoscopic surgical instrument with deflectable and rotatable distal end 失效
    内窥镜手术器具可偏转和可旋转的远端

    公开(公告)号:US5967997A

    公开(公告)日:1999-10-19

    申请号:US069763

    申请日:1998-04-30

    摘要: An endoscopic bioptome having a proximal end and a distal end includes a proximal handle assembly including first and second actuators, a distal end effector assembly having jaws for cutting tissue samples, and a hollow member extending between the handle and the end effector assembly. The hollow member includes a first axial portion extending from the proximal end to a second axial portion at the distal end of the hollow member. The second axial portion is more flexible than the first axial portion. The bioptome further includes a control member connected at the proximal end to the handle assembly and at the distal end to the end effector assembly. Actuation of the first actuator causes the control member to open and close the jaws. The bioptome further includes a deflecting device connected at the proximal end to the second actuator and extending through at least a portion of the hollow member. Actuation of the second actuator causes the deflecting device to axially displace into the second axial portion to deflect the distal end of the hollow member.

    摘要翻译: 具有近端和远端的内窥镜活检手术包括包括第一和第二致动器的近侧手柄组件,具有用于切割组织样本的钳口的远端执行器组件以及在手柄和端部执行器组件之间延伸的中空构件。 中空构件包括在中空构件的远端处从近端延伸到第二轴向部分的第一轴向部分。 第二轴向部分比第一轴向部分更柔软。 生物切割机还包括控制构件,其在近端处连接到手柄组件,并且在远端处连接到端部执行器组件。 第一致动器的致动使得控制构件打开和关闭钳口。 生物切割机还包括偏转装置,该偏转装置在近端处连接到第二致动器并且延伸穿过中空构件的至少一部分。 第二致动器的致动导致偏转装置轴向移动到第二轴向部分中以偏转中空构件的远端。

    SYSTEMS, METHODS AND COMPUTER PROGRAM PRODUCTS FOR BOOTSTRAPPING A TYPE 1 VIRTUAL MACHINE MONITOR AFTER OPERATING SYSTEM LAUNCH
    7.
    发明申请
    SYSTEMS, METHODS AND COMPUTER PROGRAM PRODUCTS FOR BOOTSTRAPPING A TYPE 1 VIRTUAL MACHINE MONITOR AFTER OPERATING SYSTEM LAUNCH 有权
    运行系统启动后1型虚拟机监控器的系统,方法和计算机程序产品

    公开(公告)号:US20140223429A1

    公开(公告)日:2014-08-07

    申请号:US13995245

    申请日:2011-12-28

    IPC分类号: G06F9/455

    CPC分类号: G06F9/45558 G06F9/4401

    摘要: Systems, methods, and computer program products that provide for the use of a type 2 VMM to de-link or isolate underlying processor hardware from an operating system. This may allow the launching of a task that requires direct access to processor hardware, where such access requires the absence of an operating system. Such a task may take the form of a type 1 VMM, such as an information security or integrity VMM, e.g., an anti-malware VMM.

    摘要翻译: 提供使用2型VMM的操作系统,方法和计算机程序产品,用于将底层处理器硬件与操作系统解耦或隔离。 这可能允许启动需要直接访问处理器硬件的任务,其中这种访问需要不存在操作系统。 这样的任务可以采取类型1 VMM的形式,诸如信息安全性或完整性VMM,例如反恶意软件VMM。