Claims (20)
OCR 11RKOCR 11RK
1. หนึ่งหรือหลายสื่อที่อ่านได้ไดยคอมพิวเตอร์ ซึ่งมีคำสั่งที่อ่านได้โดยคอมพิวเตอร์ในนั้น ซึ่งเมื่อถูก ปฏิบัติโดยอุปกรณ์คอมพิวเตอร์ จะทำให้อุปกรณ์คอมพิวเตอร์ดำเนินการการกระทำซึ่งประกอบด้วย; การระบุชี้ จากหน่วยความจำที่ไม่สามารถเข้าถึงได้โดยเอนทิตีที่ดำเนินการอยู่ภายในโหมดเอกสิทธิ์ ระบบปฏิบัติการ กลุ่มของหนึ่งหรือหลายทรัพยากรของระบบปฏิบัติการ และ การตัดสิน จากหน่วยความจำ ว่าหนึ่งหรือหลายกลุ่มของหนึ่งหรือหลายทรัพยากรได้ถูกเปลี่ยนแปลง ไปหรือไม่1. One or more computer-readable media containing computer-readable instructions which, when executed by a computer device, cause the computer device to perform actions which include: identifying a memory location inaccessible to entities operating in exclusive mode of the operating system; a group of one or more operating system resources; and deciding from memory whether one or more groups of one or more resources have been modified.
2. สื่อของข้อถือสิทธิ 1 ซึ่งการะบุชี้กลุ่มของหนึ่งหรือหลายทรัพยากรและการตัดสินว่าหนึ่งหรือ หลายกลุ่มของหนึ่งหรือหลายทรัพยากรได้ถูกเปลี่ยนเปลงไปนั้น เกิดขึ้นภายในมอนิเตอร์เครื่องเสมือนซึ่งมีเอก สิทธิ์เหนือกกว่าของโหมดเอกสิทธิ์ระบบปฏิบัติการ2. The mediation of claim 1, which identifies a group of one or more resources and determines whether one or more groups of one or more resources have been altered, occurs within a virtual machine monitor that has superior privileges to the operating system's exclusive mode.
3. สื่อของข้อถือสิทธิ 1 ซึ่งระบบปฏิบัติการดำเนินการในส่วนแบ่งที่หนึ่ง ถูกจัดโดยมอนิเตอร์เครื่อง เสมือน มอนิเตอร์เครื่องเสมือนซึ่งให้ส่วนแบ่งจำนวนมา และซึ่งระบุชี้กลุ่มของหนึ่งหรือหลายทรัพยากร และ ตัดสินว่าหนึ่งหรือหลายกลุ่มของหนึ่งหรือหลายทรัพยากรใด้ถูกเปลี่ยนแปลงไปหรือ ไม่ เกิดขึ้นภายในส่วนแบ่ง ที่สอง ซึ่งถูกจัดโดยมอนิเตอร์เครื่องเสมือน3. The media of claim 1, which the operating system executes in the first partition, is provided by the Virtual Machine Monitor. The Virtual Machine Monitor provides a number of partitions and identifies groups of one or more resources and determines whether one or more groups of one or more resources have been modified or not. This occurs within the second partition, which is provided by the Virtual Machine Monitor.
4. สื่อของข้อถือสิทธิ 1 ซึ่งยังคงประกอบด้วยการรับ ที่หน่วยความจำ ซึ่งไม่สามารถเข้าถึงได้โดย เอนทิติที่ดำเนินการอยู่ภายในไหมดเอกสิทธิ์ระบบปฏิบัติการ นโยบายการบังคับซึ่งระบุชี้กลุ่มของหนึ่งหรือ หลายทรัพยากร4. The media of claim 1, which still consists of a reception in memory that cannot be accessed by entities operating within the operating system's privileged mode; a enforcement policy that specifies a group of one or more resources.
5. สื่อของข้อถือสิทธิ 4 ซึ่งนโยบายการบังคับประกอบด้วยบัญชีรายการที่ถูกทำเครื่องหมายเชิง ดิจิตอล และซึ่งได้รับบัญชีรายการที่ถูกทำเครื่องหมายเชิงดิจิตอลและตัดสินว่าหนึ่งหรือหลายกลุ่มของหนึ่งหรือ หลายทรัพยากรได้ถูกเปลี่ยนแปลง ได้เกิดขึ้นก่อนหรือในขณะที่ระบบปฏิบัติการทำการปลุกเครื่อง (boots)5. The media of claim 4, in which the enforcement policy consists of digitally marked lists and which have received digitally marked lists and determine whether one or more groups of one or more resources have been altered, has occurred before or while the operating system boots.
6. สื่อของข้อถือสิทธิ 1 ซึ่งยังคงประกอบด้วยการแสดงตัวเชื่อมต่อโปรแกรมประยุกต์ (API) กับ ระบบปฏิบัติการและการรับการระบุชี้หนึ่งหรือหลายกลุ่มของหนึ่งหรือหลายทรัพยากรผ่าน API6. The media of claim 1, which still consists of representing the Application Programming Interface (API) with the operating system and receiving identification of one or more groups of one or more resources via API.
7. สื่อของข้อถือสิทธิ 1 ซึ่งกลุ่มของหนึ่งหรือหลายทรัพยากรรวมถึงตารางการส่งการบริการระบบ (SSDT) ตารางการส่งการระงับ (IDT) และ/หรือตารางตัวบอกโดยรวม (GDT)7. Media of Claim 1, which is a group of one or more resources including a System Service Transmission Schedule (SSDT), a Suspension Transmission Schedule (IDT), and/or a Gross Declaration Schedule (GDT).
8. สื่อของข้อถือสิทธิ 1 ซึ่งยังคงประกอบด้วยการยุติระบบปฏิบัติการ เพื่อตอบสนองการตัดสินว่า หนึ่งหรือหลายทรัพยากรของกลุ่มของหนึ่งหรือหลายทรัพยากรได้ถูกปลี่ยนเปลงไป8. The mediation of claim 1, which continues to include the termination of the operating system in response to a decision that one or more resources of a group of one or more resources have been altered.
9. สื่อของข้อถือสิทธิ 1 ซึ่งยังคงประกอบด้วยการแจ้งระบบปฏิบัติการ เมื่อมีการปลุกเครื่องใหม่ของ การดำเนินการที่ผิดกฎ เพื่อตอบสนองการตัดสินว่าหนึ่งหรือหลายทรัพยากรของกลุ่มของหนึ่งหรือหลาย ทรัพยากรได้ถูกเปลี่ยนแปลงไป9. The media of claim 1, which still includes notifying the operating system when a new operation of an illegal activity occurs, in response to a judgment that one or more resources of a group of one or more resources have been altered.
10. วิธีการ ซึ่งประกอบด้วย การเปลี่ยนแปลงประสิทธิภาพผู้จัดการการสกัดกั้นมอนิเตอร์เครื่องเสมือน เพื่อทำให้การรับของการ ระบุชี้ซึ่งหน้าหน่วยความจำหรือรีจิสเตอร์ที่เชื่อมโยงกันกับทรัพยากรระบบปฏิบัติการได้ถูกเปลี่ยนแปลงไป การรับการระบุชี้ ซึ่งหน้าหน่วยความจำหรือรือจิสเตอร์ที่เชื่อมโยงกันกับทรัพยากรระบบปฏิบัติการได้ ถูกเปลี่ยนแปลงไป และ การปิดการดำเนินการโหมดเอกสิทธิ์ระบบปฏิบัติการ เพื่อเป็นผลให้ปิดการดำเนินการระบบปฏิบัติการ ที่เชื่อมโยงกันกับทรัพยากรระบบปฏิบัติการ เพื่อตอบสนองต่อการรับของการระบุชี้นั้น10. The method involves modifying the performance of the virtual machine monitor interception manager to alter the reception of memory page or register identification associated with operating system resources. This also includes disabling OS exclusive mode operation, resulting in the closure of OS operations associated with OS resources in response to the reception of that identification.
11. วิธีการของข้อถือสิทธิ 10 ซึ่งทรัพยากรระบบปฏิบัติการคือดารางการส่งการระงับ (IDT) ที่หน้า หน่วยความจำ และรีจิสเตอร์ที่เชื่อมโยงกันกันกับทรัพยากรระบบปฏิบัติการคือรีจิสเตอร์ IDT11. Method 10, where the operating system resource is the Suspension Transmission (IDT) directory in memory and the register associated with the operating system resource is the IDT register.
12. วิธีการของข้อถือสิทธิ 10 ซึ่งทรัพยากรระบบปฏิบัติการคือตารางการส่งการบริการระบบ (SSDT) หรือตารางตัวบอกโดยรวม (GDT)12. Method 10 of claims where the operating system resources are the System Service Delivery Schedule (SSDT) or the Gross Declaration Schedule (GDT).
13. วิธีการของข้อถือสิทธิ 10 ซึ่งการปิดการดำเนินการของโหมดเอกสิทธิ์ระบบปฏิบัติการถูก ดำเนินการโดยมอนิเตอร์เครื่องเสมือน13. Method 10 of the claim, in which the exclusive mode operation of the operating system is disabled, is performed by the virtual machine monitor.
14. วิธีการของข้อถือสิทธิ 10 ซึ่งยังคงประกอบด้วยการรับนโยบายการบังคับ ซึ่งระบุชี้ทรัพยากร ระบบปฏิบัติการและหนึ่งหรือหลายทรัพยากรระบบปฏิบัติการเพิ่มเติม14. The method of claiming rights 10, which still consists of accepting the enforcement policy, specifies the operating system resources and one or more additional operating system resources.
15. วิธีการของข้อถือสิทธิ 14 ซึ่งนโยบายการบังคับยังกล่าวถึงคุณสมบัติการป้องกันที่สัมพันธ์กันกับ แต่ละทรัพยากรระบบปฏิบัติการที่ถูกระบุชี้ อย่างน้อยหนึ่งในคุณสมบัติการป้องกัน ซึ่งกล่าวถึงทรัพยากรที่ สอดคล้องกันเป็นอ่านอย่างเดียว15. The methodology of claim 14, in which the enforcement policy also addresses the protection properties associated with each identified operating system resource, includes at least one protection property that designates the corresponding resource as read-only.
16. วิธีการของข้อถือสิทธิ 15 ซึ่งยังคงประกอบด้วยการบังคับให้ทรัพยากรอยู่ในภาวะไร้การ เปลี่ยนแปลง ซึ่งสอดคคล้องกันกับคุณสมบัติการป้องกันอ่านอย่างเดียว16. The method of claim 15, which still involves enforcing the resource to remain immutable, is consistent with the read-only protection feature.
17. หนึ่งหรือหลายสื่อที่อ่านได้โดยคอมพิวเตอร์ ซึ่งมีความสามารถในการระบุชี้หนึ่งหรือหลาย ทรัพยากรระบบปฏิบัติการ ซึ่งถูกออกแบบเพื่อดำเนินการภายในโหมดเอกสิทธิ์ระบปฏิบัติการ และตัดสินว่า หนึ่งหรือหลายทรัพยากรระบบปฏิบัติการได้ถูกเปลี่ยนแปลงไปหรือไม่ ซึ่งหนึ่งหรือหลายชื่อที่อ่านได้โดย คอมพิวเตอร์อาจไม่ทำให้เกิดการโจมตีจากภายในโหมดเอกสิทธิ์ระบบปฏิบัติการ17. One or more computer-readable media capable of identifying one or more operating system resources, designed to operate within exclusive operating system mode, and determining whether one or more operating system resources have been modified, where one or more computer-readable names may not trigger an attack from within exclusive operating system mode.
18. สื่อของข้อถือสิทธิ 17 ซึ่งหนึ่งหรือหลายสื่อที่อ่านได้โดยคอมพิวเตอร์ดำเนินการอยู่ภายใน มอนิเตอร์เครื่องเสมือน ซึ่งมีความสามารถในการจำลองอุปกรณ์คอมพิวเตอร์เข้าในหนึ่งหรือหลายส่วนแบ่ง เครื่องเสมือนและเป็นแม่ข่ายส่วนแบ่งใต้ ซึ่งรวมถึงส่วนแบ่งหนึ่งซึ่งระบบปฏิบัติการที่เชื่อมโยงกันกับโหมด เอกสิทธิ์ระบบปฏิบัติการดำเนินการอยู่บนนั้น18. Media of claim 17, which one or more media readable by the computer operating within a virtual machine monitor, which has the capability to emulate computer devices into one or more virtual machine partitions and hosts sub-partitions, including one partition on which an operating system associated with an exclusive operating system mode is running.
19. สื่อของข้อถือสิทธิ 17 ซึ่งหนึ่งหรือหลายสื่อที่อ่านได้โดยคอมพิวเตอร์ดำเนินการอยู่บนอุปกรณ์ คอมพิวเตอร์ ซึ่งรวมถึงมอนิเตอร์เครื่องเสมือน มอนิเตอร์เครื่องเสมือนเพื่อจำลองอุปกรณ์คอมพิวเตอร์เข้าใน อย่างน้อยส่วนแบ่งเครื่องเสมือนที่หนึ่งและส่วนแบ่งเครื่องเสมือนที่สอง และเพื่อเป็นแม่ข่ายส่วนแบ่งเครื่อง เสมือนที่หนึ่งและส่วนแบ่งเครื่องเสมือนที่สอง และซึ่งระบบปฏิบัติการที่เชื่อมโยงกันกับโหมดเอกสิทธิ์ ระบบปฏิบัติการอาศัยอยู่ภายในส่วนแบ่งที่หนึ่ง และหนึ่งหรือหลายสื่อที่อ่านได้โดยคอมพิวเตอร์อาศัยอยู่ ภายในส่วนแบ่งที่สอง19. The media of claim 17, which one or more computer-readable media operate on a computer device, including a virtual machine monitor, a virtual machine monitor to emulate the computer device into at least the first and second virtual machine segments, and to host the first and second virtual machine segments, and in which an operating system linked to the exclusive mode of the operating system resides within the first segment, and one or more computer-readable media reside within the second segment.
20. สื่อของข้อถือสิทธิ 17 ซึ่งหนึ่งหรือหลายสื่อที่อ่านได้โดยคอมพิวเตอร์ยังคงมีความสามามารถในการ ปิดการดำเนินการระบบปฏิบัติการที่เชื่อมโยงกันกับกับโหมดเอกสิทธิ์ระบบปฏิบัติการ เพื่อตอบสนองต่อการ ตัดสินว่าหนึ่งหรือหลายของหนึ่งหรือหลายระบปฏิบัติการได้ถูกเปลี่ยนแปลงไป20. The media of claim 17, where one or more media readable by a computer retain the ability to shut down the operating system operations associated with the operating system's exclusive mode in response to a decision that one or more of the operating systems have been modified.