Claims (20)
------25/12/2561------(OCR) หน้า 1 ของจำนวน 2 หน้าข้อถือสิทธิ 1. วิธีการประกอบด้วย การทำเสมือนหนึ่งหรือหลายตัวประมวลผลทางคอมพิวเตอร์จริงไปเป็นตัวประมวลผลทางคอมพิวเตอร์เสมือน ซึ่งแต่ละอันเกี่ยวของกับพาร์ติชันที่เกี่ยวข้อง ตัวประมวลผลทางคอมพิวเตอร์เสมือนนั้นประกอบด้วย ตัวประมวลผลเสมือนทางระบบปฏิบัติการ ปฏิบัติการในโหมดอภิสิทธิ์มอนิเตอร์เครื่อง เสมือน เกี่ยวข้องกับพาร์ติชันแรก และมีอภิสิทธิ์ที่จะปรับเปลี่ยนหน่วยความจำทาง ระบบปฎิบัติการของตนเองและใช้ส่วนย่อยของความกว้างแถบความกี่ทางการประมวลผลของ หนึ่งหรือหลายตัวประมวลผลทางคอมพิวเตอร์จริงที่ปฎิบัติการโหมดอภิสิทธิ์ทาง ระบบปฏิบัติการ และ ตัวประมวลผลเสมือนทางเอเยนต์การป้องกัน ปฏิบัติการในโหมดอภิสิทธิ์ทางเอเยนต์ การป้องกัน เกี่ยวข้องกับพาร์ติชันที่สองและมือภิสิทธิ์ที่จะปรับเปลี่ยนหน่วยความจำเอเยนต์การ ป้องกันของตนเองและใช้ส่วนย่อยที่แตกต่างกันของความกว้างแถบความถี่การประมวลผลของ หนึ่งหรือหลายตัวประมวลผลคอมพิวเตอร์จริง หน่วยความจำเอเยนต์การป้องกัน เข้าไม่ถึงจาก ตัวประมวลผลเสมือนทางระบบปฏิบัติการ และ การทำให้ตัวประมวลผลเสมือนทางเอเยนต์การป้องกันต้องดำเนินการเอเยนต์การป้องกันที่อาศัยอยู่ในพาร์ติชันที่สองเพื่อกำหนดว่าส่วนย่อยของหน่วยความจำระบบปฏิบัติการดามที่กล่าวได้ถูกปรับเปลี่ยนหรือไม่ ที่ซึ่ง โหมดอภิสิทธิ์ที่างเอเยนต์การป้องกันมีอภิสิทธิมากกว่าโหมดอภิสิทธิที่างระบบปฎิบัติการแต่มือภิสิทธิ์น้อยกว่าโหมดอภิสิทธิมอนิเตอร์เครื่องเสมือน 2. วิธีการตามข้อถือสิทธิที่ 1 ยังประกอบด้วย การปรับเปลี่ยนตัวอัดการทางการสกัดนั้นของมอนิเตอร์เครื่องเสมือนที่มีประสิทธิภาพในการเปิดใช้งานการรับของการระบุว่าส่วนย่อยของหน่วยความจำระบบปฏิบัติการได้ถูกปรับเปลี่ยน หน่วยย่อยของหน่วยความจำระบบปฏิบัติการถูกตั้งไว้ภายในพาร์ติชันที่หนึ่ง การรับมาโดยตัวอัดการทางการสกัดนั้นของมอนิเตอร์เครื่องเสมือน การระบุว่าเอเยนต์การป้องกันกำหนดว่าส่วนย่อยของหน่วยความจำระบบปฏิบัติการตามที่กล่าวได้ถูกปรับเปลี่ยน และ เพื่อตอบสนองต่อการรับมาของการระบุ การปิดระบบปฎิบัติการที่สอดคล้องหน้า 2 ของจำนวน 2 หน้า3. วิธีการตามข้อถือสิทธิที่ 1 ที่ซึ่ง การทำให้ตัวประมวลผลเสมือนทางระบบปฎิบํตการของเอเยนต์การป้องกันเพื่อดำเนินงานเอเยนต์การป้องกัน ประกอบตัวย การทำให้ตัวประมวลผลเสมือนทางเอเยนต์การป้องกันต้องดำเนินงานเอเยนต์การป้องกันที่ช่วงเวลาที่ถูกเจาะจง4. วิธีการตามข้อถือสิทธิที่ 1 ที่ซึ่ง ตัวประมวลผลเสมือนทางเอเยนต์การป้องกันถูกทุ่มเท5 เฉพาะเพื่อการดำเนินงานเอเยนต์การป้องกัน5. วิธีการตามข้อถือสิทธิที่ 1 ที่ซึ่ง ตัวประมวลผลเสมือนทางเอเยนต์การป้องกันถูกกำหนดการเวลาโดยมอนิเตอร์เครื่องเสมือนและโปร่งใสต่อระบบปฏิบตการที่เกี่ยวข้องกับหน่วยความจำระบบปฏิบตการตามที่กล่าว ------------ ------31/01/2561------(OCR) หน้า 1 ของจำนวน 4 หน้า ข้อถือสิทธิ 1. หนึ่งหรือหลายอุปกรณ์เก็บข้อมูลที่อ่านได้ทางคอมพิวเตอร์ที่มีคำสั่งการที่อ่านได้ทาง คอมพิวเตอร์ในที่นี้ที่ เมื่อถูกดำเนินการโดยอุปกรณ์ทางคอมพิวเตอร์ ทำให้อุปกรณ์ทางคอมพิวเตอร์ต้อง ปฏิม่ตการการกระทำ ที่ประกอบด้วย การรับมาที่มอนิเตอร์เครื่องเสมือนปฏิบัติการในโหมดอภิสิทธิทางมอนิเตอร์เครื่องเสมือน คำร้อง ขอให้ช่วงของหน่วยความจำถูกทำให้ไม่สามารถปรับเปลี่ยนได้หรือเข้าไม่ถึงจากโหมดอภิสิทธิทาง ระบบปฏิป้ตการ การทำให้ช่วงของหน่วยความจำไม่สามารถปรับเปลี่ยนได้หรือเข้าไม่ถึงจากโหมดอภิสิทธิทาง ระบบปฏิบัติการและ การดำเนินงานเอเยนต์การป้องกันซึ่งปฏิบัติการในโหมดอภิสิทธิที่างเอเยนต์การป้องกัน ที่อาศัย อยู่ภายในช่วงของหน่วยความจำ ที่ซึ่ง เอเยนต์การป้องกันถูกกำหนดคำให้รับนโยบายกังศับใข้ ที่ อธิบาย หนึ่งหรือหลายทรัพยากร ที่ปฏิบัติการในพาร์ติข้นแรก, หนึ่งหรือหลายทรัพยากร เข้าถึงได้จาก โหมดอภิสิทธิทางระบบปฏิบัติการ และเพื่อตอบสนองต่อการรับมาของนโยบายกังศับใช้, กำหนด, ด้วย การใช้ของนโยบายกังศับใช้ และจากช่วงของหน่วยความจำที่อาศัยอยู่กับพาร์ติข้นที่สองที่เข้าไม่ถึงจาก โหมดอภิสิทธิทางระบบปฏิบัติการ ไม่ว่าจะหนึ่งหรือหลายของหนึ่งหรือหลายทรัพยากรที่ปฏิบัติการอยู่ ในพาร์ติข้นแรกถูกปรับเปลี่ยน ที่ซึ่งโหมดอภิสิทธิทางเอเยนต์การป้องกันเป็นอภิสิทธิมากกว่าโหมด อภิสิทธิที่างระบบปฏิบัติการ แต่อภิสิทธินอยกว่าโหมดอภิสิทธิที่างมอนิเตอร์เครื่องเสมือน 2. หนึ่งหรือหลายอุปกรณ์เก็บข้อมูลที่อ่านได้ทางคอมพิวเตอร์ตามข้อถือสิทธิที่ 1 ที่กัง ประกอบด้วยการตํ่งคำด้วกับเวลาเพื่อดำเนินงานเอเยนต์การป้องกัน 3. หนึ่งหรือหลายอุปกรณ์เก็บข้อมูลที่อ่านได้ทางคอมพิวเตอร์ตามข้อถือสิทธิที่ 2 ที่ซึ่งด้ว กับเวลาสังการมอนิเตอร์เครื่องเสมือนให้ดำเนินงานเอเยนต์การป้องกันที่ช่วงเวลาปกติ 4. หนึ่งหรือหลายอุปกรณ์เก็บข้อมูลที่อ่านได้ทางคอมพิวเตอร์ตามข้อถือสิทธิที่ 1 ที่กัง ประกอบด้วยการปิดระบบปฏิบัติการที่เกี่ยวข้องกับโหมดอภิสิทธิทางระบบปฏิบัติการ เพื่อตอบสนองต่อ การกำหนดโดยเอเยนต์การป้องกัน ที่หนึ่งหรือหลายของหนึ่งหรือหลายทรัพยากรถูกปรับเปลี่ยน นโยบายกังศับใข้นโยบายกังศับใข้ 5. หนึ่งหรือหลายอุปกรณ์เก็บข้อมูลที่อ่านได้ทางคอมพิวเตอร์ตามข้อถือสิทธิที่ 1 ที่ซึ่ง หนึ่งหรือหลายของทรัพยากรรวมถึง system service dispatch table (SSDT), interrupt dispatch table (IDT) หรือ global descriptor table (GDT) หน้า 2 ของจำนวน 4 หน้า 6. หนึ่งหรือหลายอุปกรณ์เก็บข้อมูลที่อ่านได้ทางคอมพิวเตอร์ตามข้อถือสิทธิที่ 1 ที่ด้ง ประกอบด้วยการร้บมาที่มอนิเตอร์เครื่องเสมือน และหด้งจากการดำเนินงานของเอเยนต์การป้องก็น การแจ้งเตือนว่าเอเยนต์การป้องด้นสำเร็จการดำเนินงาน 7. หนึ่งหรือหลายอุปกรณ์เก็บข้อมูลที่อ่านได้ทางคอมพิวเตอร์ตามข้อถือสิทธิที่ 1 ที่ด้ง ประกอบด้วยการปิดระบบปฏิบตการที่เกี่ยวข้องด้บโหมดอภิสิทธิที่างระบบปฏิป้ตการเพื่อตอบสนองต่อ การพยายามเข้าถึงขอช่วงของหน่วยความจำหรือเอเยนต์การป้องด้น จากโหมดอภิสิทธิทาง ระบบปฏิป้ตการ 8. หนึ่งหรือหลายอุปกรณ์เก็บข้อมูลที่อ่านได้ทางคอมพิวเตอร์ตามข้อถือสิทธิที่ 1 ที่ด้ง ประกอบด้วยการหมุนรอบระหว่างการดำเนินงานของเอเยนต์การป้องด้น และการไม่ดำเนินงานเอเยนต์ การป้องด้นเพื่อที่อย่างน้อยที่สุดเมื่อเอเยนต์การป้องด้นดำเนินงาน ด้นไม่สามารถปรับเปลี่ยนได้หรือเข้า ไม่ถึงจากโหมดอภิสิทธิที่างระบบปฏิปตการ 9. วิธีการประกอบด้วย การทำเสมือนหนึ่งหรือหลายด้วประมวลผลทางคอมพิวเตอร์จริงไปเป็นด้วประมวลผลทาง คอมพิวเตอร์เสมือน ซึ่งแต่ละด้นเกี่ยวของด้บพาร์ตืข้นที่เกี่ยวข้อง ด้วประมวลผลทางคอมพิวเตอร์เสมือน นั้นประกอบด้วย ด้วประมวลผลเสมือนทางระบบปฏิบ้ตการ ปฏิบตการในโหมดอภิสิทธิมอนิเตอร์เครื่อง เสมือน เกี่ยวข้องกับพาร์ติข้นแรก และมีอภิสิทธิ'ที่จะปรับเปลี่ยนหน่วยความจำทาง ระบบปฏิป้ตการของตนเองและใช้ส่วนย่อยของความกว้างแถบความถี่ทางการประมวลผลของ หนึ่งหรือหลายตัวประมวลผลทางคอมพิวเตอร์จริงที่ปฏิด้ตืการ โหมดอภิสิทธิทาง ระบบปฏิป้ตการ และ ด้วประมวลผลเสมือนทางเอเยนต์การป้องด้น ปฏิบ้ดการ'ในโหมดอภิสิทธิ'ทางเอเยนต์ การป้องด้น เกี่ยวข้องด้บพาร์ติข้นที่สองและมือภิสิทธิที่จะปรับเปลี่ยนหน่วยความจำเอเยนต์การ ป้องด้นของตนเองและใช้ส่วนย่อยที่แตกต่างด้นของความกว้างแถบความถี่การประมวลผลของ หนึ่งหรือหลายด้วประมวลผลคอมพิวเตอร์จริง หน่วยความจำเอเยนต์การป้องด้น เข้าไม่ถึงจาก ตัวประมวลผลเสมือนทางระบบปฎิบํตการ และ การทำให้ตัวประมวลผลเสมือนทางเอเยนต์การป้องด้นต้องดำเนินการเอเยนต์การป้องด้นที่ อาศ้ยอยู่ในพาร์ติข้นที่สองเพื่อกำหนดว่าส่วนย่อยของหน่วยความจำระบบปฏิบํตการตามที่กล่าวได้ถูก ปรับเปลี่ยนหรือไม่ หน้า 3 ของจำนวน 4 หน้า 10. วิธีการตามข้อถือสิทธิที่ 9 ยงประกอบด้วย การปรับเปลี่ยนตัวจัดการทางการสกัดกั้นของมอนิเตอร์เครื่องเสมือนที่มืประสิทธิภาพในภาร เปิดใช้งานการรับของการระบุว่าส่วนย่อยของหน่วยความจำระบบปฏิป้ตการได้ถูกปรับเปลี่ยน หน่วย ย่อยของหน่วยความจำระบบปฏิบัติการถูกกั้งไวVทยในพาร์ติข้นที่หนึ่ง การรับมาโดยตัวจัดการทางการสกัดกั้นของมอนิเตอร์เครื่องเสมือน การระบุว่าเอเยนต์การ ป้องกันกำหนดว่าส่วนย่อยของหน่วยความจำระบบปฏิบดการตามที่กล่าวได้ถูกปรับเปลี่ยน และ เพื่อตอบสนองต่อการรับมาของการระบุ การปิดระบบปฏิป้ตการที่สอดคล้อง 11. วิธีการตามข้อถือสิทธิที่ 9 ที่ซึ่ง การทำให้ตัวประมวลผลเสมือนทางระบบปฏิป้ตการต้อง ดำเนินงาน ประกอบด้วย การทำให้ด้วประมวลผลเสมือนทางเอเยนต์การป้องกันต้องดำเนินงานเอเยนต์ การป้องกันที่ช่วงเวลาที่ถูกเจาะจง 12. วิธีการตามข้อถือสิทธิที่ 9 ที่ซึ่ง ตัวประมวลผลเสมือนทางเอเยนต์การป้องกันถูกทุ่มเท เฉพาะเพื่อการดำเนินงานเอเยนต์การป้องกัน 13. วิธีการตามข้อถือสิทธิที่ 9 ที่ซึ่ง ตัวประมวลผลเสมือนทางเอเยนต์การป้องกันถูกกำหนดการ เวลาโดยมอนิเตอร์เครื่องเสมือนและโปร่งใสต่อระบบปฏิบัติการที่เกี่ยวข้องกับหน่วยความจำ ระบบปฏิบํตการตามที่กล่าว 14. หนึ่งหรือหลายอุปกรณ์เก็บข้อมูลที่อ่านได้ทางคอมพิวเตอร์ที่มืคำสั่งการที่อ่านได้ทาง คอมพิวเตอร์!นที่นี้'ที่ เมื่อถูกดำเนินงานโดยอุปกรณ์ทางคอมพิวเตอร์ที่ประกอบด้วยตัวประมวลผลทาง กายภาพพื้นฐาน ที่รวมถึงหนึ่งหรือหลายโหมดอภิสิทธิ ทำให้อุปกรณ์ทางคอมพิวเตอร์ต้องเพิ่มโหมด อภิสิทธิที่ไม่ได้แสดงบนตัวประมวลผลทางกายภาพพื้นฐาน โดยการเรียกมอนิเตอร์เครื่องเสมือนเพื่อร้อง ขอช่วงของหน่วยความจำที่เกี่ยวข้องกับเอเยนต์การป้องกันของโหมดอภิสิทธิที่เพิ่มมาให้ ถูกทำให้ ปรับเปลี่ยนไม่ได้หรือเข้าไม่ถึงจากโหมดอภิสิทธิอน โหมดอภิสิทธิที่เพิ่มมาถูกกำหนดคำให้เพิ่มและ ดำเนินการคำสั่งที่ไม่ได้ดำเนินงานมาก่อนหน้านี้ บนตัวประมวลผลทางกายภาพพื้นฐาน ที่ซึ่งหนึ่งหรือหลายโหมดอภิสิทธิแสดงให้เห็นตอนเริ่มด้นบนตัวประมวลผลทางกายภาพพื้นฐาน รวมถึงโหมดอภิสิทธิ'ผูใข้ และโหมดอภิสิทธิที่างระบบปฏิป้ตการ และที่ซึ่งโหมดอภิสิทธิที่ถูกเพิ่มเข้าไปมื อภิสิทธิ'มากกว่าโหมดอภิสิทธิ'ผูใข้ แต่อภิสิทธินี้อยกว่าโหมดอภิสิทธิที่างระบบปฏิป้ติการ หน้า 4 ของจำนวน 4 หน้า 15. หนึ่งหรือหลายอุปกรณ์เก็บข้อมูลที่อ่านได้ทางคอมพิวเตอร์ตามข้อถือสิทธิที่ 14 ที่ซึ่งโหมด อภิสิทธิที่ถูกเพิ่มเข้าไป สามารถปรับเปลี่ยนส่วนย่อยของหน่วยความจำของอุปกรณ์ทางคอมพิวเตอร์ ที่ แตกต่างจากส่วนย่อยของหน่วยความจำที่สามารถปรับเปลี่ยนค่าได้โดยหนึ่งหรือหลายโหมดอภิสิทธิที่ แสดงตอนเริ่มด้นบนตัวประมวลผลทางกายภาพพื้นฐาน ------------------25/12/2018------(OCR) Page 1 of 2 Claims 1. The method consists of virtualizing one or more physical computer processors into virtual computer processors, each associated with a related partition. The virtual computer processors consist of: an Operating System virtual processor, operating in privileged monitor mode, associated with the first partition, and having the privilege to modify its own Operating System memory and use a portion of the processing bandwidth of one or more physical computer processors operating in privileged Operating System mode; and a Protection Agent virtual processor, operating in privileged Protection Agent mode, associated with the second partition, and having the privilege to modify its own Protection Agent memory and use a different portion of the processing bandwidth of one or more physical computer processors. Protection Agent memory is inaccessible from... The operating system virtual processor and the protection agent virtual processor must execute the protection agent operating system ... Method pursuant to Claim 1 where the Protection Agent virtual processor is dedicated solely to Protection Agent operations. Method pursuant to Claim 1 where the Protection Agent virtual processor is scheduled by the Virtual Machine Monitor and is transparent to the operating system's associated operating system memory as stated. ------------ ------31/01/2018------(OCR) Page 1 of 4 Claim 1. One or more computer-readable storage devices containing computer-readable instructions herein, when executed by the computer device, cause the computer device to perform actions which include: receiving access to the Virtual Machine Monitor in privileged mode; requesting that a range of memory be made immutable or inaccessible from privileged mode in the operating system; making a range of memory immutable or inaccessible from privileged mode in the operating system; and The protection agent's operation, which functions in privileged mode, resides within a memory area where the protection agent is assigned to receive a security policy that describes one or more resources operating in the first partition, one or more resources accessible in OS privileged mode. In response to the acceptance of the security policy, it is determined, by the application of the security policy, and from a memory area residing on the second partition inaccessible from OS privileged mode, one or more of the resources operating in the first partition are modified where the protection agent's privileged mode is more privileged than the OS privileged mode. However, the privileges are less than those of the virtual machine monitoring privilege mode. 2. One or more computer-readable storage devices under claim 1 that are time-sensitive to operate the protection agent. 3. One or more computer-readable storage devices under claim 2 that are time-sensitive to operate the virtual machine monitoring protection agent at regular intervals. 4. One or more computer-readable storage devices under claim 1 that are time-sensitive to operate the operating system associated with the operating system privilege mode in response to a determination by the protection agent that one or more of one or more resources are modified. Policy 5. One or more computer-readable storage devices under Policy 1 in which one or more of the resources including the system service dispatch table (SSDT), interrupt dispatch table (IDT), or global descriptor table (GDT) are accessed. Page 2 of 4. 6. One or more computer-readable storage devices under Policy 1 in which one or more of the resources including ... 8. One or more computer-readable storage devices under claim 1, comprising rotation between operating and non-operating agent protection modes, so that at least when the agent protection is operating, the device cannot be modified or accessed from the operating system's privileged mode. 9. The method consists of virtualizing one or more physical computer processors into virtual computer processors, each relating to a specific partition. These virtual computer processors consist of an operating system virtual processor operating in privileged mode, a virtual machine monitor relating to the first partition, and have the privilege to modify its own operating system memory and use a portion of the processing bandwidth of one or more physical computer processors operating in privileged operating system mode and an agent protection virtual processor. Operating in 'privileged mode' as an agent, protection involves a second partition and the privilege to modify its own agent protection memory and use different subsets of the processing bandwidth of one or more physical computer processors. Agent protection memory is inaccessible from the operating system virtual processor, and enabling the agent protection virtual processor to operate the agent protection residing in the second partition determines whether the said subset of operating system memory has been modified. Page 3 of 4, page 10. The method under claim 9 also involves modifying the virtual machine monitor interception manager to enable the reception of the indication that a subset of operating system memory has been modified. The subset of operating system memory is located in the first partition. Reception by the virtual machine monitor interception manager indicates that the agent protection... 11. The method under claim 9 in which the operating system virtual processor is required to operate consists of the operation of the protection agent virtual processor, which is required to operate the protection agent at a specified time. 12. The method under claim 9 in which the protection agent virtual processor is dedicated solely to the operation of the protection agent. 13. The method under claim 9 in which the protection agent virtual processor is timed by the virtual machine monitor and is transparent to the operating system's memory-related operations as described. 14. One or more computer-readable storage devices containing computer-readable instructions, which, when executed by a computer device comprising a physical underlying processor, include one or more privilege modes, cause the computer device to add privilege modes not represented on the physical underlying processor by calling the virtual machine monitor to request them. A portion of memory associated with the protection agent of an added privilege mode is made immutable or inaccessible from the privilege mode. The added privilege mode is defined to add and execute instructions that have not been previously executed on the underlying physical processor where one or more privilege modes are represented at startup on the underlying physical processor, including user privilege mode and operating privilege mode, and where the added privilege mode has more privileges than user privilege mode but less privileges than operating privilege mode. Page 4 of 4, page 15. One or more computer read-only storage devices pursuant to claim 14 where the added privilege mode can modify a portion of the computer device's memory that is different from the portion of memory that can be modified by one or more privilege modes represented at startup on the underlying physical processor.
1. หนึ่งหรือหหลายสื่อที่อ่านได้ทางคอมพิวเตอร์ที่มีคำสั่งการที่อ่านได้ทางคอมพิวเตอร์ใน ที่นี้ซึ่ง เมื่อถูกกระทำการโดยอุปกรณ์ทางคอมพิวเตอร์ (102) ทำให้อุปกรณ์ทางคอมพิวเตอร์ (102) เพื่อ ปฏิบัติกิจกรรมประกอบด้วย การรับมา (902) ที่มอนิเตอร์เครื่องเสมือน (108) คำร้องชอซึ่งพิสัยของหน่วยความตำ (206, 306) ถูกทำให้ปรับเปลี่ยนไม่ได้หรือเข้าไม่ถึงจากภาวะเอกสิทธิ์ทางระบบปฏิบัติการ (126) การทำให้ (904) พิสัยของหน่วยความจำ (206,306) ถูกทำให้ปรับเปลี่ยนไม่ได้หรือเข้าไม่ถึง จากภาวะเอกสิทธิ์ทางระบบปฏิบัติการ (126) และ การดำเนินงาน (908) เอเยนต์การป้องกัน (144) ซึ่งอาศัยอยู่ภายในพิสัยของหน่วยความจำ (206,306)1. One or more computer-readable media containing computer-readable instructions herein which, when executed by a computer device (102), enables the computer device (102) to perform activities including receiving (902) at the virtual machine monitor (108), requests whose memory range (206, 306) is immutable or inaccessible from OS privileges (126), making (904) the memory range (206, 306) immutable or inaccessible from OS privileges (126), and operating (908) the protection agent (144) which resides within the memory range (206, 306).
2. สื่อของข้อถือสิทธิที่ 1 ยังประกอบด้วยการตั้งค่า (904) ตัวจับเวลาเพื่อดำเนินงานเอ เยนต์การป้องกัน (144)2. The media of claim 1 also includes the settings (904), the timer to perform the protection agent operation (144).
3. สื่อของข้อถือสิทธิ์ที่ 2 ในสิ่งซึ่งตัวจับเวลานั้นสั่งการมอนิเตอร์เครื่องเสมือน (108) เพื่อ ดำเนินงานเอเยนต์การป้องกัน (144) นั้นที่ช่วงเวลาปกติ3. The media of the second claim in which the timer commands the virtual machine (108) to operate the protection agent (144) at regular intervals.
4. สื่อของข้อถือสิทธิ์ที่ 1 ในสิ่งซึ่งเอเยนต์การป้องกัน (144) ถูกกำหนดโครงแบบเพื่อรับ (906) นโยบายทางการบังคับที่ทำการอธิบายหนึ่งหรือหลายทรัพยากร (120) ที่เข้าถึงได้จากภาะเอก สิทธิ์ทางระบบปฏิบัติการ (126) และในการตอบสนองต่อการรับนโยบายทางการบังคับ พิจารณาว่า (910) หนึ่งหรือหลายของหนึ่งหรือหลายทรัพยากร (120) ได้ถูกปรับเปลี่ยนหรือไม่4. The mediation of claim 1 in which the defense agent (144) is configured to receive (906) an enforcement policy that describes one or more resources (120) accessible from the operating system privileges (126) and in response to receiving the enforcement policy, consider whether (910) one or more of the one or more resources (120) have been modified.
5. สื่อของข้อถือสิทธิ์ที่ 4 ยังประกอบด้วยการปิดระบบ (912) ต่อระบบปฏิบัติการ (144) ที่ เกี่ยวข้องกับภาวะเอกสิทธิ์ทางระบบปฏิบัติการ (126) ในการตอบสนองต่อการพิจารณาโดยเอเยนต์การ ป้องกัน (144) ซึ่งหนึ่งหรือหลายของหนึ่งหรือหลายทรัพยากร (120) ได้ถูกปรับเปลี่ยน5. The media of claim 4 also includes the shutdown (912) of the operating system (144) relating to operating system exclusivity (126) in response to consideration by the protection agent (144) in which one or more of one or more resources (120) have been modified.
6. สื่อของข้อถือสิทธิ์ที่ 4 ในสิ่งซึ่งหนึ่งหรือหลายทรัพยากร (120) รวมไปถึง service dispatch table (SSDT), interrupt dispatch table (IDT) หรือ global descriptor table (GDT)6. The media of claim 4 in which one or more resources (120) include the service dispatch table (SSDT), interrupt dispatch table (IDT) or global descriptor table (GDT).
7. สื่อของข้อถือสิทธิ์ที่ 1 ยังประกอบด้วยการรับมา (914) ที่มอนิเตอร์เครื่องเสมือน (108) และหลังจาการดำเนินงาน (908) ของเอเยนต์การป้องกัน (144) การประกาศซึ่งเอเยนต์การป้องกัน (144) ได้สำเร็จการดำเนินงาน7. The media of claim 1 also includes the receipt (914) at the virtual machine monitor (108) and, following the execution (908) of the defense agent (144), the declaration in which the defense agent (144) has successfully completed the execution.
8. สื่อของข้อถือสิทธิ์ที่ 1 ยังประกอบด้วยการปิดระบบปฏิบัติการ (144) ที่เกี่ยวข้องกับ ภาวะเอกสิทธิทางระบบปฏิบัติการ (126) ในการตอบสนองต่อการเข้าถึงที่ถูกพยายาม จากภาวะเอก สิทธิ์ทางระบบปฏิบัติการ (126) พิสัยของหน่วยความจำ (206,306) หรือเอเยนต์การป้องกัน (144)8. The media of claim 1 also includes the shutdown of the operating system (144) associated with operating system privileges (126) in response to attempted access by the operating system privileges (126), memory range (206,306), or protection agent (144).
9. สื่อของข้อถือสิทธิ์ที่ 1 ยังประกอบด้วยการทำงานเป็นรอบ (916) ระหว่างการ ดำเนินงาน (908) ของเอเยนต์การป้องกัน (144) นั้นและการไม่ได้ดำเนินงานเอเยนต์การป้องกัน (144) เพื่อที่อย่างน้อยที่สุดเมื่อเอเยนต์การป้องกัน (144) ดำเนินงานมันให้ปรับเปลี่ยนไม่ได้หรือเข้าไม่ถึงจาก ภาวะเอกสิทธิ์ทางระบบปฏิบัติการ (126)9. The media of claim 1 also consists of the cycle of operation (916) between the operation (908) of the defense agent (144) and the non-operation of the defense agent (144) so that, at least when the defense agent (144) is operating, it is immutable or inaccessible from the operating system's privileges (126).
10. วิธีหนึ่งประกอบด้วย การทำเสมือน (1002) หนึ่งหรือหลายตัวประมวลผลทางคอมพิวเตอร์จริง (104(a),104(b)) ไป เป็นตัวประมวนผลทางคอมพิวเตอร์เสมือน (506, 508, 510) ตัวประมวลผลทางคอมพิวเตอร์เสมือน (506,508,510) นั้นประกอบด้วย หนึ่งหรือหลายตัวประมวลผลเสมือนทางระบบปฏิบัติการ (506,508) แต่ละตัวมีเอก สิทธิ์ที่จะปรับเปลี่ยนหน่วยความจำทางระบบปฏิบัติการของตนเองและใช้ส่วนย่อยของความ กว้างแถบความถี่ทางการประมวลผลของ (6000) หนึ่งหรือหลายตัวประมวลผลทางคอมพิวเตอร์ จริง (104(a), 104(b)) และ อย่างน้อยที่สุด หนึ่งตัวประมวลผลเสมือนทางเอเยนต์การป้องกัน (510) มีเอกสิทธิ์ที่จะ ปรับเปลี่ยนหน่วยความจำทางเอเยนต์การป้องกันของตนเองและใช้ส่วนย่อยที่แตกต่างของ ความกว้างแถบความถี่ทางการประมวลผล (6000) ของหนึ่งหรือหลายตัวประมวลผลทาง คอมพิวเตอร์จริง (104(a),104(b)) และ การทำให้ (1004) ตัวประมวลผลเสมือนทางเอเยนต์การป้องกัน (510) เพื่อกระทำการเอเยนต์ การป้องกัน (144) ให้ได้ผลเพื่อพิจารณาว่าส่วนย่อยของหน่วยความจำทางระบบปฏิบัติการตามที่กล่าว ได้ถูกปรับเปลี่ยนหรือไม่10. One method consists of virtualizing (1002) one or more real computer processors (104(a),104(b)) into virtual computer processors (506, 508, 510). These virtual computer processors (506,508,510) consist of one or more OS virtual processors (506,508), each having the privilege to modify its own OS memory and use a subset of the processing bandwidth (6000) of one or more real computer processors (104(a), 104(b)) and at least one protection agent virtual processor (510), having the privilege to modify its own protection agent memory and use a subset of the processing bandwidth (6000) of one or more real computer processors. (104(a),104(b)) and making (1004) the virtual processor for the protection agent (510) to perform the protection agent (144) to determine whether the aforementioned OS memory subset has been modified.
11. วิธีของข้อถือสิทธิที่ 10 ยังประกอบด้วย การรับ (1006) การระบุว่าเอเยนต์การป้องกัน (144) ได้ถูกพิจารณาว่าส่วนย่อยของ หน่วยความจำทางระบบปฏิบัติการตามที่กล่าวได้ถูกปรับเปลี่ยน และ ในการตอบสนองต่อการรับรองของการระบุค่านั้น การปิดระบบ (1008) กับระบบปฏิบิติการที่ สอดคล้อง (114)11. The method of claim 10 also involves the acceptance (1006) of the indication that the protection agent (144) has been deemed to have modified the aforementioned OS memory subset, and in response to the acceptance of that indication, the system (1008) is shut down to the corresponding operating system (114).
12. วิธีของข้อถือสิทธิที่ 10 ในสิ่งซึ่งหนึ่งหลายตัวประมวลผลเสมือนทาง ระบบปฏิบัติการ (506,508) นั้นไม่มีความสามารถของการปรับเปลี่ยนค่าหน่วยความจำทางเอเยนต์การ ป้องกัน12. Method of claim number 10 in which one or more virtual processors in the operating system (506, 508) do not have the ability to modify agent memory values for protection.
13. วิธีของข้อถือสิทธิที่ 10 ในสิ่งซึ่งการทำให้ (1004) ของตัวประมวลผลเสมือนเอเยนต์ การป้องกัน (510) เพื่อการทำการเอเยนต์การป้องกัน (144) ประกอบด้วยการทำให้ตัวประมวลผล เสมือนทางเอเยนต์การป้องกัน (510) เพื่อกระทำการเอเยนต์การป้องกัน (144) ที่ช่วงเวลาที่ถูกเจาะจง13. The method of claim 10 in which the activation of the protection agent virtual processor (510) to perform protection agent (144) is to activate the protection agent virtual processor (510) to perform protection agent (144) at a specified time.
14. วิธีของข้อถือสิทธิที่ 10 ในสิ่งซึ่งตัวประมวลผลเสมือนทางเอเยนต์การป้องกัน (510) ถูก ทำเฉพาะกิจเพียงเพื่อการกระทำการเอเยนต์การป้องกัน (144) นั้น14. Method of claim 10 in which the virtual protection agent processor (510) is performed ad-hoc only for the purpose of performing protection agent operations (144).
15. วิธีของข้อถือสิทธิที่ 10 ในสิ่งซึ่งตัวประมวลผลเสมือนทางเอเยนต์การป้องกัน (510) ถูก ทำตารางเวลาโดยมอนิเตอร์เครื่องเสมือน (108) และเปิดเผยต่อระบบปฏิบัติการ (144) ที่เกี่ยวกับ หน่วยความจำทางระบบปฏิบัติการตามที่กล่าว15. Method of claim 10 in which the agent protection virtual processor (510) is scheduled by the virtual machine monitor (108) and exposed to the operating system (144) in relation to the operating system memory as stated.
16. หนึ่งหรือหลายสื่อที่อ่านได้ทางคอมพิวเตอร์ที่มีคำสั่งการที่อ่านได้ทางคอมพิวเตอร์ในที่นี้ ซึ่ง ซึ่งเมื่อถูกกระทำการโดยอุปกรณ์ทางคอมพิวเตอร์ (102) ประกอบด้วยตัวประมวลผลทางกายภาพ ภายใต้นั้น (104) ซึ่งรวมไปถึงหนึ่งหรือหลายภาวะเอกสิทธิ์ ทำให้อุปกรณ์ทางคอมพิวเตอร์ (102) เพื่อ เพิ่ม (1104) ภาวะเอกสิทธิ์ซึ่งไม่ได้แสดงให้เห็นบนตัวประมวลผลทางกายภาพใต้นั้น (104) นั้น16. One or more computer-readable media containing computer-readable instructions herein, which, when executed by a computer device (102) contains a physical processor under there (104), which includes one or more exclusive rights, enables the computer device (102) to add (1104) exclusive rights which are not shown on the physical processor under there (104).
17. สื่อของข้อถือสิทธิที่ 16 ในสิ่งซึ่งภาวะเอกสิทธิ์ที่ถูกเพิ่มเข้าไปมีความสามารถของการ ปรับเปลี่ยนส่วนย่อยของหน่วยความจำของอุปกรณ์ทางคอมพิวเตอร์ (102) ซึ่งแตกต่างกว่าส่วนย่อย ของหน่วยความจำซึ่งปรับเปลี่ยนค่าโดยหนึ่งหรือหลายภาวะเอกสิทธิ์ซึ่งแสดงให้เห็นตอนเริ่มต้นบนตัว ประมวลผลทางกายภาพภายใต้นั้น (104)17. The media of claim 16 in which an added privilege is capable of modifying a portion of the memory of the computer device (102) different from the portion of memory modified by one or more privileges initially shown on the underlying physical processor (104).
18. สื่อของข้อถือสิทธิที่ 16 ในสิ่งซึ่งหนึ่งหรือหลายภาวะเอกสิทธิ์ซ่งแสดงให้เห็นตอนเริ่มต้น บนตัวประมวลผลทางกายภาพภายใต้นั้น (104) รวมไปถึงภาวะเอกสิทธิ์ทางผู้ใช้ (128) และภาวะเอก สิทธิ์ทางระบบปฏิบัติการ (126) และในสิ่งซึ่งภาวะเอกสิทธิ์ที่ถูกเพิ่มเข้าไปมีเอกสิทธิ์มากกว่าทั้งภาวะ เอกสิทธิ์ทางผู้ใช้ (128) และภาวะเอกสิทธิ์ทางระบบปฏิบัติการ (126)18. The media of claim 16 in which one or more privileges which are initially displayed on the underlying physical processor (104) include the user privilege (128) and the operating system privilege (126), and in which the added privileges have more privileges than both the user privilege (128) and the operating system privilege (126).
19. สื่อของข้อถือสิทธิ์ที่ 16 ในสิ่งซึ่งหนึ่งหรือหลายภาวะเอกสิทธิ์ซึ่งแสดงให้เห็นตอนเริ่มต้น บนตัวประมวลผลทางกายภาพภายใต้นั้น (104) รวมไปถึงภาวะเอกสิทธิ์ทางผู้ใช้ (128) และภาวะเอก สิทธิ์ทางระบบปฏิบัติการ (126) และในสิ่งซึ่งภาวะเอกสิทธิ์ที่ถูกเพิ่มเข้าไปมีเอกสิทธิ์มากกว่าภาวะเอก สิทธิ์ทางผู้ใช้ (128) แต่เอกสิทธิ์น้อยกว่าภาวะเอกสิทธิ์ทางระบบปฏิบัติการ (126)19. The media of claim 16 in which one or more privileges expressed at the outset on the underlying physical processor (104) include the user privilege (128) and the operating system privilege (126), and in which the added privileges are more exclusive than the user privilege (128) but less exclusive than the operating system privilege (126).
20. สื่อของข้อถือสิทธิ์ที่ 16 ในสิ่งซึ่งหนึ่งหรือหลายภาวะเอกสิทธิ์ซึ่งแสดงให้เห็นตอนเริ่มต้น บนตัวประมวลผลทางกายภาพภายใต้นั้นรวมไปถึงภาวะเอกสิทธิ์ทางระบบปฏิบัติการ (126) และการ เพิ่มของภาวะเอกสิทธิ์ประกอบไปด้วยการเรียกมอนิเตอร์เครื่องเสมือน (108) เพื่อร้องขอถึงพิสัยของ หน่วยความจำ (206,306) ที่เกี่ยวข้องกับเอเยนต์การป้องกัน (144) ถูกทำให้ปรับเปลี่ยนไม่ได้หรือเข้า ไม่ถึงจากภาวะเอกสิทธิ์ทางระบบปฏิบัติการ (126)20. The media of claim 16 in which one or more privileges expressed at the start on the physical processor under it, including OS privilege (126) and the addition of privileges consisting of a virtual machine monitor call (108) to request a range of memory (206,306) associated with the protection agent (144) is made immutable or inaccessible from OS privilege (126).