TH95155A - Operating system resource protection - Google Patents

Operating system resource protection

Info

Publication number
TH95155A
TH95155A TH701006673A TH0701006673A TH95155A TH 95155 A TH95155 A TH 95155A TH 701006673 A TH701006673 A TH 701006673A TH 0701006673 A TH0701006673 A TH 0701006673A TH 95155 A TH95155 A TH 95155A
Authority
TH
Thailand
Prior art keywords
operating system
resources
media
virtual machine
computer
Prior art date
Application number
TH701006673A
Other languages
Thai (th)
Other versions
TH61425B (en
TH95155B (en
Inventor
แกนกูลี่ จอย
ซินฮา ซูยาช
คัทเลอร์ เดวิด
เบเคอร์ เบรนดอน
ฟอลทซ์ ฟอร์เรสต์
เอ ฟิลด์ สก็อต
เทราท์ อีริค
Original Assignee
นางสาวสยุมพร สุจินตัย
นายธีรพล สุวรรณประทีป
ไมโครซอฟต์ เทคโนโลยี ไลเซ็นซิ่ง
Filing date
Publication date
Publication of TH95155A publication Critical patent/TH95155A/en
Application filed by นางสาวสยุมพร สุจินตัย, นายธีรพล สุวรรณประทีป, ไมโครซอฟต์ เทคโนโลยี ไลเซ็นซิ่ง filed Critical นางสาวสยุมพร สุจินตัย
Publication of TH61425B publication Critical patent/TH61425B/en
Publication of TH95155B publication Critical patent/TH95155B/en

Links

Abstract

DC60 เอกสารนี้ได้กล่าวถึงเครื่องมือซึ่งมีความสามารถในการทำให้ตัวป้องกันสามารถตัดสิน จาก หน่วยความจำที่ไม่สามารถเข้าถึงได้จากโหมดเอกสิทธิ์ระบบปฏิบัติการ ว่าหนึ่งหรือหลายทรัพยากรของ ระบบปฏิบัติการได้ถูกดัดแปลงไป ในบางกรณี เครื่องมือเหล่านี้อาจทำให้ตัวป้องกันสามารถอาศัยอยู่ภายใน มอนิเตอร์เครื่องเสมือนได้ ในกรณีอื่นๆ เครื่องมืออาจทำให้ตัวป้องกันสามารถอาศัยอยู่ภายในส่วนแบ่งเสมือน ซึ่งถูกจัดโดยมอนิเตอร์เครื่องเสมือนที่แยกออกไป โดยการดำเนินการด้านนอกของโหมดเอกสิทธิ์ ระบบปฏิบัติการนี้ ตัวป้องกันอาจถูกโจมตีได้ยากขึ้นจากเอนทิตีที่ดำเนินการอยู่ภายในโหมดเอกสิทธิ์ ระบบปฏิบัติการThis DC60 document describes tools capable of enabling the protector to determine, from memory inaccessible to OS exclusive mode, whether one or more OS resources have been modified. In some cases, these tools may allow the protector to reside within a virtual machine monitor. In other cases, the tools may allow the protector to reside within a virtual share provided by an isolated virtual machine monitor. By operating outside of OS exclusive mode, the protector may be more difficult to attack from entities operating within OS exclusive mode.

Claims (20)

OCR 11RKOCR 11RK 1. หนึ่งหรือหลายสื่อที่อ่านได้ไดยคอมพิวเตอร์ ซึ่งมีคำสั่งที่อ่านได้โดยคอมพิวเตอร์ในนั้น ซึ่งเมื่อถูก ปฏิบัติโดยอุปกรณ์คอมพิวเตอร์ จะทำให้อุปกรณ์คอมพิวเตอร์ดำเนินการการกระทำซึ่งประกอบด้วย; การระบุชี้ จากหน่วยความจำที่ไม่สามารถเข้าถึงได้โดยเอนทิตีที่ดำเนินการอยู่ภายในโหมดเอกสิทธิ์ ระบบปฏิบัติการ กลุ่มของหนึ่งหรือหลายทรัพยากรของระบบปฏิบัติการ และ การตัดสิน จากหน่วยความจำ ว่าหนึ่งหรือหลายกลุ่มของหนึ่งหรือหลายทรัพยากรได้ถูกเปลี่ยนแปลง ไปหรือไม่1. One or more computer-readable media containing computer-readable instructions which, when executed by a computer device, cause the computer device to perform actions which include: identifying a memory location inaccessible to entities operating in exclusive mode of the operating system; a group of one or more operating system resources; and deciding from memory whether one or more groups of one or more resources have been modified. 2. สื่อของข้อถือสิทธิ 1 ซึ่งการะบุชี้กลุ่มของหนึ่งหรือหลายทรัพยากรและการตัดสินว่าหนึ่งหรือ หลายกลุ่มของหนึ่งหรือหลายทรัพยากรได้ถูกเปลี่ยนเปลงไปนั้น เกิดขึ้นภายในมอนิเตอร์เครื่องเสมือนซึ่งมีเอก สิทธิ์เหนือกกว่าของโหมดเอกสิทธิ์ระบบปฏิบัติการ2. The mediation of claim 1, which identifies a group of one or more resources and determines whether one or more groups of one or more resources have been altered, occurs within a virtual machine monitor that has superior privileges to the operating system's exclusive mode. 3. สื่อของข้อถือสิทธิ 1 ซึ่งระบบปฏิบัติการดำเนินการในส่วนแบ่งที่หนึ่ง ถูกจัดโดยมอนิเตอร์เครื่อง เสมือน มอนิเตอร์เครื่องเสมือนซึ่งให้ส่วนแบ่งจำนวนมา และซึ่งระบุชี้กลุ่มของหนึ่งหรือหลายทรัพยากร และ ตัดสินว่าหนึ่งหรือหลายกลุ่มของหนึ่งหรือหลายทรัพยากรใด้ถูกเปลี่ยนแปลงไปหรือ ไม่ เกิดขึ้นภายในส่วนแบ่ง ที่สอง ซึ่งถูกจัดโดยมอนิเตอร์เครื่องเสมือน3. The media of claim 1, which the operating system executes in the first partition, is provided by the Virtual Machine Monitor. The Virtual Machine Monitor provides a number of partitions and identifies groups of one or more resources and determines whether one or more groups of one or more resources have been modified or not. This occurs within the second partition, which is provided by the Virtual Machine Monitor. 4. สื่อของข้อถือสิทธิ 1 ซึ่งยังคงประกอบด้วยการรับ ที่หน่วยความจำ ซึ่งไม่สามารถเข้าถึงได้โดย เอนทิติที่ดำเนินการอยู่ภายในไหมดเอกสิทธิ์ระบบปฏิบัติการ นโยบายการบังคับซึ่งระบุชี้กลุ่มของหนึ่งหรือ หลายทรัพยากร4. The media of claim 1, which still consists of a reception in memory that cannot be accessed by entities operating within the operating system's privileged mode; a enforcement policy that specifies a group of one or more resources. 5. สื่อของข้อถือสิทธิ 4 ซึ่งนโยบายการบังคับประกอบด้วยบัญชีรายการที่ถูกทำเครื่องหมายเชิง ดิจิตอล และซึ่งได้รับบัญชีรายการที่ถูกทำเครื่องหมายเชิงดิจิตอลและตัดสินว่าหนึ่งหรือหลายกลุ่มของหนึ่งหรือ หลายทรัพยากรได้ถูกเปลี่ยนแปลง ได้เกิดขึ้นก่อนหรือในขณะที่ระบบปฏิบัติการทำการปลุกเครื่อง (boots)5. The media of claim 4, in which the enforcement policy consists of digitally marked lists and which have received digitally marked lists and determine whether one or more groups of one or more resources have been altered, has occurred before or while the operating system boots. 6. สื่อของข้อถือสิทธิ 1 ซึ่งยังคงประกอบด้วยการแสดงตัวเชื่อมต่อโปรแกรมประยุกต์ (API) กับ ระบบปฏิบัติการและการรับการระบุชี้หนึ่งหรือหลายกลุ่มของหนึ่งหรือหลายทรัพยากรผ่าน API6. The media of claim 1, which still consists of representing the Application Programming Interface (API) with the operating system and receiving identification of one or more groups of one or more resources via API. 7. สื่อของข้อถือสิทธิ 1 ซึ่งกลุ่มของหนึ่งหรือหลายทรัพยากรรวมถึงตารางการส่งการบริการระบบ (SSDT) ตารางการส่งการระงับ (IDT) และ/หรือตารางตัวบอกโดยรวม (GDT)7. Media of Claim 1, which is a group of one or more resources including a System Service Transmission Schedule (SSDT), a Suspension Transmission Schedule (IDT), and/or a Gross Declaration Schedule (GDT). 8. สื่อของข้อถือสิทธิ 1 ซึ่งยังคงประกอบด้วยการยุติระบบปฏิบัติการ เพื่อตอบสนองการตัดสินว่า หนึ่งหรือหลายทรัพยากรของกลุ่มของหนึ่งหรือหลายทรัพยากรได้ถูกปลี่ยนเปลงไป8. The mediation of claim 1, which continues to include the termination of the operating system in response to a decision that one or more resources of a group of one or more resources have been altered. 9. สื่อของข้อถือสิทธิ 1 ซึ่งยังคงประกอบด้วยการแจ้งระบบปฏิบัติการ เมื่อมีการปลุกเครื่องใหม่ของ การดำเนินการที่ผิดกฎ เพื่อตอบสนองการตัดสินว่าหนึ่งหรือหลายทรัพยากรของกลุ่มของหนึ่งหรือหลาย ทรัพยากรได้ถูกเปลี่ยนแปลงไป9. The media of claim 1, which still includes notifying the operating system when a new operation of an illegal activity occurs, in response to a judgment that one or more resources of a group of one or more resources have been altered. 10. วิธีการ ซึ่งประกอบด้วย การเปลี่ยนแปลงประสิทธิภาพผู้จัดการการสกัดกั้นมอนิเตอร์เครื่องเสมือน เพื่อทำให้การรับของการ ระบุชี้ซึ่งหน้าหน่วยความจำหรือรีจิสเตอร์ที่เชื่อมโยงกันกับทรัพยากรระบบปฏิบัติการได้ถูกเปลี่ยนแปลงไป การรับการระบุชี้ ซึ่งหน้าหน่วยความจำหรือรือจิสเตอร์ที่เชื่อมโยงกันกับทรัพยากรระบบปฏิบัติการได้ ถูกเปลี่ยนแปลงไป และ การปิดการดำเนินการโหมดเอกสิทธิ์ระบบปฏิบัติการ เพื่อเป็นผลให้ปิดการดำเนินการระบบปฏิบัติการ ที่เชื่อมโยงกันกับทรัพยากรระบบปฏิบัติการ เพื่อตอบสนองต่อการรับของการระบุชี้นั้น10. The method involves modifying the performance of the virtual machine monitor interception manager to alter the reception of memory page or register identification associated with operating system resources. This also includes disabling OS exclusive mode operation, resulting in the closure of OS operations associated with OS resources in response to the reception of that identification. 11. วิธีการของข้อถือสิทธิ 10 ซึ่งทรัพยากรระบบปฏิบัติการคือดารางการส่งการระงับ (IDT) ที่หน้า หน่วยความจำ และรีจิสเตอร์ที่เชื่อมโยงกันกันกับทรัพยากรระบบปฏิบัติการคือรีจิสเตอร์ IDT11. Method 10, where the operating system resource is the Suspension Transmission (IDT) directory in memory and the register associated with the operating system resource is the IDT register. 12. วิธีการของข้อถือสิทธิ 10 ซึ่งทรัพยากรระบบปฏิบัติการคือตารางการส่งการบริการระบบ (SSDT) หรือตารางตัวบอกโดยรวม (GDT)12. Method 10 of claims where the operating system resources are the System Service Delivery Schedule (SSDT) or the Gross Declaration Schedule (GDT). 13. วิธีการของข้อถือสิทธิ 10 ซึ่งการปิดการดำเนินการของโหมดเอกสิทธิ์ระบบปฏิบัติการถูก ดำเนินการโดยมอนิเตอร์เครื่องเสมือน13. Method 10 of the claim, in which the exclusive mode operation of the operating system is disabled, is performed by the virtual machine monitor. 14. วิธีการของข้อถือสิทธิ 10 ซึ่งยังคงประกอบด้วยการรับนโยบายการบังคับ ซึ่งระบุชี้ทรัพยากร ระบบปฏิบัติการและหนึ่งหรือหลายทรัพยากรระบบปฏิบัติการเพิ่มเติม14. The method of claiming rights 10, which still consists of accepting the enforcement policy, specifies the operating system resources and one or more additional operating system resources. 15. วิธีการของข้อถือสิทธิ 14 ซึ่งนโยบายการบังคับยังกล่าวถึงคุณสมบัติการป้องกันที่สัมพันธ์กันกับ แต่ละทรัพยากรระบบปฏิบัติการที่ถูกระบุชี้ อย่างน้อยหนึ่งในคุณสมบัติการป้องกัน ซึ่งกล่าวถึงทรัพยากรที่ สอดคล้องกันเป็นอ่านอย่างเดียว15. The methodology of claim 14, in which the enforcement policy also addresses the protection properties associated with each identified operating system resource, includes at least one protection property that designates the corresponding resource as read-only. 16. วิธีการของข้อถือสิทธิ 15 ซึ่งยังคงประกอบด้วยการบังคับให้ทรัพยากรอยู่ในภาวะไร้การ เปลี่ยนแปลง ซึ่งสอดคคล้องกันกับคุณสมบัติการป้องกันอ่านอย่างเดียว16. The method of claim 15, which still involves enforcing the resource to remain immutable, is consistent with the read-only protection feature. 17. หนึ่งหรือหลายสื่อที่อ่านได้โดยคอมพิวเตอร์ ซึ่งมีความสามารถในการระบุชี้หนึ่งหรือหลาย ทรัพยากรระบบปฏิบัติการ ซึ่งถูกออกแบบเพื่อดำเนินการภายในโหมดเอกสิทธิ์ระบปฏิบัติการ และตัดสินว่า หนึ่งหรือหลายทรัพยากรระบบปฏิบัติการได้ถูกเปลี่ยนแปลงไปหรือไม่ ซึ่งหนึ่งหรือหลายชื่อที่อ่านได้โดย คอมพิวเตอร์อาจไม่ทำให้เกิดการโจมตีจากภายในโหมดเอกสิทธิ์ระบบปฏิบัติการ17. One or more computer-readable media capable of identifying one or more operating system resources, designed to operate within exclusive operating system mode, and determining whether one or more operating system resources have been modified, where one or more computer-readable names may not trigger an attack from within exclusive operating system mode. 18. สื่อของข้อถือสิทธิ 17 ซึ่งหนึ่งหรือหลายสื่อที่อ่านได้โดยคอมพิวเตอร์ดำเนินการอยู่ภายใน มอนิเตอร์เครื่องเสมือน ซึ่งมีความสามารถในการจำลองอุปกรณ์คอมพิวเตอร์เข้าในหนึ่งหรือหลายส่วนแบ่ง เครื่องเสมือนและเป็นแม่ข่ายส่วนแบ่งใต้ ซึ่งรวมถึงส่วนแบ่งหนึ่งซึ่งระบบปฏิบัติการที่เชื่อมโยงกันกับโหมด เอกสิทธิ์ระบบปฏิบัติการดำเนินการอยู่บนนั้น18. Media of claim 17, which one or more media readable by the computer operating within a virtual machine monitor, which has the capability to emulate computer devices into one or more virtual machine partitions and hosts sub-partitions, including one partition on which an operating system associated with an exclusive operating system mode is running. 19. สื่อของข้อถือสิทธิ 17 ซึ่งหนึ่งหรือหลายสื่อที่อ่านได้โดยคอมพิวเตอร์ดำเนินการอยู่บนอุปกรณ์ คอมพิวเตอร์ ซึ่งรวมถึงมอนิเตอร์เครื่องเสมือน มอนิเตอร์เครื่องเสมือนเพื่อจำลองอุปกรณ์คอมพิวเตอร์เข้าใน อย่างน้อยส่วนแบ่งเครื่องเสมือนที่หนึ่งและส่วนแบ่งเครื่องเสมือนที่สอง และเพื่อเป็นแม่ข่ายส่วนแบ่งเครื่อง เสมือนที่หนึ่งและส่วนแบ่งเครื่องเสมือนที่สอง และซึ่งระบบปฏิบัติการที่เชื่อมโยงกันกับโหมดเอกสิทธิ์ ระบบปฏิบัติการอาศัยอยู่ภายในส่วนแบ่งที่หนึ่ง และหนึ่งหรือหลายสื่อที่อ่านได้โดยคอมพิวเตอร์อาศัยอยู่ ภายในส่วนแบ่งที่สอง19. The media of claim 17, which one or more computer-readable media operate on a computer device, including a virtual machine monitor, a virtual machine monitor to emulate the computer device into at least the first and second virtual machine segments, and to host the first and second virtual machine segments, and in which an operating system linked to the exclusive mode of the operating system resides within the first segment, and one or more computer-readable media reside within the second segment. 20. สื่อของข้อถือสิทธิ 17 ซึ่งหนึ่งหรือหลายสื่อที่อ่านได้โดยคอมพิวเตอร์ยังคงมีความสามามารถในการ ปิดการดำเนินการระบบปฏิบัติการที่เชื่อมโยงกันกับกับโหมดเอกสิทธิ์ระบบปฏิบัติการ เพื่อตอบสนองต่อการ ตัดสินว่าหนึ่งหรือหลายของหนึ่งหรือหลายระบปฏิบัติการได้ถูกเปลี่ยนแปลงไป20. The media of claim 17, where one or more media readable by a computer retain the ability to shut down the operating system operations associated with the operating system's exclusive mode in response to a decision that one or more of the operating systems have been modified.
TH701006673A 2016-03-09 Aerosol products for gel composition formation TH95155B (en)

Publications (3)

Publication Number Publication Date
TH95155A true TH95155A (en) 2009-04-09
TH61425B TH61425B (en) 2018-03-15
TH95155B TH95155B (en) 2023-08-03

Family

ID=

Similar Documents

Publication Publication Date Title
US10447728B1 (en) Technique for protecting guest processes using a layered virtualization architecture
US9021597B2 (en) Security arrangements for extended USB protocol stack of a USB host system
KR101626424B1 (en) System and method for virtual machine monitor based anti-malware security
EP2521062B1 (en) Protecting operating-system resources
KR101946982B1 (en) Process Evaluation for Malware Detection in Virtual Machines
US8380987B2 (en) Protection agents and privilege modes
US9032525B2 (en) System and method for below-operating system trapping of driver filter attachment
CA2527526C (en) Computer security management, such as in a virtual machine or hardened operating system
CN101673215B (en) Computer and user management method in virtual environment
US20120255003A1 (en) System and method for securing access to the objects of an operating system
US20130097655A1 (en) Methods and apparatus for a safe and secure software update solution against attacks from malicious or unauthorized programs to update protected secondary storage
US8635664B2 (en) Method and system for securing application program interfaces in unified extensible firmware interface
EP4428731A1 (en) Kernel protecting method, apparatus and system
US12475250B2 (en) Data protection method and apparatus, storage medium, and computer device
TH61425B (en) Operating system resource protection
CN101071388B (en) Process-isolation control system and method
JP6623656B2 (en) Communication control device, communication control method, and communication control program
Kuzuno et al. Identification of kernel memory corruption using kernel memory secret observation mechanism
WO2025189909A1 (en) Application processing method and apparatus, and attack defense system
Sato et al. Complicating process identification by replacing process information for attack avoidance
Nagano et al. An Intrusion Detection System which can Restore Altered Data
TH95156A (en) Defense Agent and Privilege Mode
KR20090005661A (en) Massmailing Worm Blocking Device and Method