IP Library Granted Patent US 8,281,393
Granted Patent B2
US 8,281,393 · App. 11/594,095 · Granted Oct 2, 2012

Method and system for detecting windows rootkit that modifies the kernel mode system service dispatch table

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,281,393
App. No.
11/594,095
Granted
Oct 2, 2012
Kind
B2
Abstract

A method, system, and computer program product for detecting a kernel-mode rootkit that hooks the System Service Dispatch Table (SSDT) is secure, avoids false positives, and does not disable security applications. A method for detecting a rootkit comprises the steps of calling a function that accesses a system service directly, receiving results from calling the function that accesses the system service directly, calling a function that accesses the system service indirectly, receiving results from calling the function that accesses the system service indirectly, and comparing the received results from calling the function that accesses the system service directly and the received results from calling the function that accesses the system service indirectly to determine presence of a rootkit.

Claims (56)

1. A computer-implemented method for detecting a rootkit, comprising:

identifying a plurality of real addresses within an operating system kernel by accessing a plurality of kernel export tables, wherein the plurality of real addresses are associated with a kernel mode Nt function;

scanning a system service dispatch table (SSDT) in order to determine if unwanted modifications have occurred in the SSDT, wherein the scanning includes comparing the plurality of real addresses with a plurality of addresses within the SSDT;

determining a real address of a function that accesses a system service directly from inside the kernel for comparison with another address;

calling the function that accesses the system service directly;

receiving results from calling the function that accesses the system service directly;

calling a function that accesses the system service indirectly;

receiving results from calling the function that accesses the system service indirectly; and

comparing the received results from calling the function that accesses the system service directly and the received results from calling the function that accesses the system service indirectly to determine presence of a rootkit, wherein the function that accesses the system service directly is the kernel mode Nt function, and the function that accesses the system service indirectly is a user mode Nt function or a Zw function.

2. The method of claim 1 , wherein the step of calling the function that accesses the system service indirectly comprises the steps of:

calling a function that obtains an address of the function that accesses a system service directly; and

calling the function that accesses a system service directly using the obtained address.

3. The method of claim 1 , wherein a particular address in the table of the function that accesses a system service directly has been replaced with an address of a rootkit function.

4. The method of claim 3 , wherein the rootkit function is operable to hide a process, a thread, a file or a registry entry.

5. The method of claim 1 , wherein a particular address of the kernel mode Nt function is obtained from the SSDT.

6. The method of claim 5 , wherein the particular address in the SSDT of the kernel mode Nt function has been replaced with an address of a rootkit function.

7. The method of claim 6 , wherein the rootkit function is operable to hide a process, a thread, a file or a registry entry.

8. The method of claim 1 , wherein the real address is determined for comparison by accessing a kernel export table.

9. The method of claim 1 , wherein the scanning includes comparing the real address with an address in the system service dispatch table.

10. A system for detecting a rootkit comprising:

a processor operable to execute computer program instructions;

a memory operable to store computer program instructions executable by the processor such that the system is configured for:

identifying a plurality of real addresses within an operating system kernel by accessing a plurality of kernel export tables, wherein the plurality of real addresses are associated with a kernel mode Nt function;

scanning a system service dispatch table (SSDT) in order to determine if unwanted modifications have occurred in the SSDT, wherein the scanning includes comparing the plurality of real addresses with a plurality of addresses within the SSDT;

determining a real address of a function that accesses a system service directly from inside the kernel for comparison with another address;

calling the function that accesses the system service directly;

receiving results from calling the function that accesses the system service directly;

calling a function that accesses the system service indirectly;

receiving results from calling the function that accesses the system service indirectly; and

comparing the received results from calling the function that accesses the system service directly and the received results from calling the function that accesses the system service indirectly to determine presence of a rootkit, wherein the function that accesses the system service directly is the kernel mode Nt function, and the function that accesses the system service indirectly is a user mode Nt function or a Zw function.

11. The system of claim 10 , wherein the step of calling the function that accesses the system service indirectly comprises the steps of:

calling a function that obtains an address of the function that accesses a system service directly; and

calling the function that accesses a system service directly using the obtained address.

12. The system of claim 10 , wherein a particular address in the table of the function that accesses a system service directly has been replaced with an address of a rootkit function.

13. The system of claim 12 , wherein the rootkit function is operable to hide a process, and a thread.

14. The system of claim 10 , wherein a particular address of the kernel mode Nt function is obtained from the system service dispatch table.

15. The system of claim 14 , wherein the particular address in the system service dispatch table of the kernel mode Nt function has been replaced with an address of a rootkit function.

16. The system of claim 15 , wherein the rootkit function is operable to hide a file or a registry entry.

17. A computer program product for detecting a rootkit comprising:

a non-transitory computer readable storage medium;

computer program instructions, recorded on the non-transitory computer readable storage medium:

identifying a plurality of real addresses within an operating system kernel by accessing a plurality of kernel export tables, wherein the plurality of real addresses are associated with a kernel mode Nt function;

scanning a system service dispatch table (SSDT) in order to determine if unwanted modifications have occurred in the SSDT, wherein the scanning includes comparing the plurality of real addresses with a plurality of addresses within the SSDT;

determining a real address of a function that accesses a system service directly from inside the kernel for comparison with another address;

calling the function that accesses the system service directly;

receiving results from calling the function that accesses the system service directly;

calling a function that accesses the system service indirectly;

receiving results from calling the function that accesses the system service indirectly; and

comparing the received results from calling the function that accesses the system service directly and the received results from calling the function that accesses the system service indirectly to determine presence of a rootkit, wherein the function that accesses the system service directly is the kernel mode Nt function, and the function that accesses the system service indirectly is a user mode Nt function or a Zw function.

18. The computer program product of claim 17 , wherein the step of calling the function that accesses the system service indirectly comprises the steps of:

calling a function that obtains an address of the function that accesses a system service directly; and

calling the function that accesses a system service directly using the obtained address.

19. The computer program product of claim 17 , wherein a particular address in the table of the function that accesses a system service directly has been replaced with an address of a rootkit function.

20. The computer program product of claim 17 , wherein a particular address of the kernel mode Nt function is obtained from the system service dispatch table.

21. The computer program product of claim 20 , wherein a particular address in the system service dispatch table of the kernel mode Nt function has been replaced with an address of a rootkit function.

22. The computer program product of claim 21 , wherein the rootkit function is operable to hide a process, a thread, a file and a registry entry.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2006
From: SALLAM, AHMED
To: MCAFEE, INC.
Reel/Frame 018531/0826 →