IP Library Granted Patent US 7,581,220
Granted Patent B1
US 7,581,220 · App. 11/285,272 · Granted Aug 25, 2009

System and method for modifying user memory from an arbitrary kernel state

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,581,220
App. No.
11/285,272
Granted
Aug 25, 2009
Kind
B1
Abstract

A system, method, and computer-accessible medium for modifying user memory from an arbitrary kernel state are disclosed. The kernel may generate a modification to the context of the process. Subsequently, the kernel may pass control to the process in user mode, and further, the process may pass control from the user mode to the kernel in response to the modification of the context of the process. The kernel may then modify the process memory from kernel mode.

Claims (54)

1. A method for modifying a process memory for a process executing in user mode, the method comprising:

generating a modification to a context of the process from kernel mode;

passing control to the process in user mode after generating the modification to the context of the process;

passing control from user mode to kernel mode in response to the modification to the context of the process; and

modifying the process memory from kernel mode after passing control from user mode to kernel mode.

2. The method of claim 1 ,

wherein control is passed to the process in user mode and back to kernel mode without executing an instruction in user mode.

3. The method of claim 1 ,

wherein modifying the process memory comprises setting a breakpoint in the process.

4. The method of claim 1 ,

wherein generating the modification to the context of the process comprises setting a program counter to point to an invalid address.

5. The method of claim 1 ,

wherein the modification to the context of the process is generated from kernel mode in a CPU interrupt state.

6. The method of claim 1 ,

wherein the modification to the context of the process is generated from kernel mode in an arbitrary kernel state.

7. The method of claim 1 ,

restoring the context of the process after modifying the process memory by undoing the modification to the context of the process.

8. A system comprising:

a processor; and

a memory coupled to the processor, wherein the memory comprises a process memory for a process executing in user mode, and wherein the memory stores program instructions which are executable by the processor to:

generate a modification to a context of the process from kernel mode;

pass control to the process in user mode after generating the modification to the context of the process;

pass control from user mode to kernel mode in response to the modification to the context of the process; and

modify the process memory from kernel mode after passing control from user mode to kernel mode.

9. The system of claim 8 ,

wherein control is passed to the process in user mode and back to kernel mode without executing an instruction in user mode.

10. The system of claim 8 ,

wherein, in modifying the process memory, the program instructions are further executable by the processor to set a breakpoint in the process.

11. The system of claim 8 ,

wherein, in generating the modification to the context of the process, the program instructions are further executable by the processor to set a program counter to point to an invalid address.

12. The system of claim 8 ,

wherein the modification to the context of the process is generated from kernel mode in a CPU interrupt state.

13. The system of claim 8 ,

wherein the modification to the context of the process is generated from kernel mode in an arbitrary kernel state.

14. A computer-accessible memory medium comprising program instructions for modifying a process memory for a process executing in user mode, wherein the program instructions are computer-executable to implement:

generating a modification to a context of the process from kernel mode;

passing control to the process in user mode after generating the modification to the context of the process;

passing control from user mode to kernel mode in response to the modification to the context of the process; and

modifying the process memory from kernel mode after passing control from user mode to kernel mode.

15. The computer-accessible memory medium of claim 14 ,

wherein control is passed to the process in user mode and back to kernel mode without executing an instruction in user mode.

16. The computer-accessible memory medium of claim 14 ,

wherein modifying the process memory comprises setting a breakpoint in the process.

17. The computer-accessible memory medium of claim 14 ,

wherein generating the modification to the context of the process comprises setting a program counter to point to an invalid address.

18. The computer-accessible memory medium of claim 14 ,

wherein the modification to the context of the process is generated from kernel mode in a CPU interrupt state.

19. The computer-accessible memory medium of claim 14 ,

wherein the modification to the context of the process is generated from kernel mode in an arbitrary kernel state.

20. A system for modifying a process memory for a process executing in user mode, the system comprising:

means for generating a modification to a context of the process from kernel mode;

means for passing control to the process in user mode after generating the modification to the context of the process;

means for passing control from user mode to kernel mode in response to the modification to the context of the process; and

means for modifying the process memory from kernel mode after passing control from user mode to kernel mode.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2015
From: SYMANTEC OPERATING CORPORATION
To: SYMANTEC CORPORATION
Reel/Frame 036199/0642 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED ON REEL 019872 FRAME 979. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNEE IS SYMANTEC OPERATING CORPORATION. Recorded Mar 5, 2012
From: VERITAS OPERATING CORPORATION
To: SYMANTEC OPERATING CORPORATION
Reel/Frame 027819/0462 →
CHANGE OF NAME Recorded Sep 26, 2007
From: VERITAS OPERATING CORPORATION
To: SYMANTEC CORPORATION
Reel/Frame 019872/0979 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2005
From: ROECK, GUENTER E.
To: VERITAS OPERATING CORPORATION
Reel/Frame 017258/0466 →