IP Library Granted Patent US 9,069,586
Granted Patent B2
US 9,069,586 · App. 13/273,002 · Granted Jun 30, 2015

System and method for kernel rootkit protection in a hypervisor environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,069,586
App. No.
13/273,002
Granted
Jun 30, 2015
Kind
B2
Abstract

A system and method for rootkit protection in a hypervisor environment includes modules for creating a soft whitelist having entries corresponding to each guest kernel page of a guest operating system in a hypervisor environment, wherein each entry is a duplicate page of the corresponding guest kernel page, generating a page fault when a process attempts to access a guest kernel page, and redirecting the process to the corresponding duplicate page. If the page fault is a data page fault, the method includes fixing the page fault, and marking a page table entry corresponding to the guest kernel page as non-executable and writeable. If the page fault is an instruction page fault, the method includes marking a page table entry corresponding to the guest kernel page as read-only. Redirecting changing a machine page frame number in a shadow page table of the hypervisor to point to the corresponding duplicate page.

Claims (56)

1. A method, comprising:

creating a soft whitelist having an entry corresponding to a guest kernel page of a guest operating system (OS) in a hypervisor environment comprising a hypervisor, wherein the entry is a duplicate page of the guest kernel page, and the guest OS has not loaded at least some kernel components;

mapping a virtual base address of the guest kernel page to a machine page frame number of the corresponding duplicate page;

generating a page fault when a process attempts to access the guest kernel page; and

redirecting the process to the duplicate page corresponding to the guest kernel page if the page fault is an instruction page fault.

2. The method of claim 1 , wherein the redirecting comprises changing a machine page frame number in a shadow page table of the hypervisor to point to the duplicate page corresponding to the guest kernel page.

3. The method of claim 1 , further comprising:

if the page fault is a data page fault:

fixing the page fault; and

marking a page table entry corresponding to the guest kernel page as non-executable and writeable.

4. The method of claim 1 , further comprising:

if the page fault is the instruction page fault, marking a page table entry corresponding to the guest kernel page as read-only.

5. The method of claim 1 , further comprising:

marking a page table entry of the guest kernel page as NOT_PRESENT in a shadow page table of the hypervisor.

6. The method of claim 1 , further comprising:

setting a lockdown feature bit in the hypervisor during a domain creation to enable rootkit protection.

7. An apparatus, comprising:

a memory; and

a processor configured to create a soft whitelist having an entry corresponding to a guest kernel page of a guest OS in a hypervisor environment comprising a hypervisor, wherein the entry is a duplicate page of the guest kernel page,

the processor is further configured to map a virtual base address of the guest kernel page to a machine page frame number of the corresponding duplicate page, the guest OS has not loaded at least some kernel components, and

the processor is further configured to generate a page fault when a process attempts to access the guest kernel page, and to redirect the process to the duplicate page corresponding to the guest kernel page if the page fault is an instruction page fault.

8. The apparatus of claim 7 , wherein the processor redirects the process by changing a machine page frame number in a shadow page table of the hypervisor to point to the duplicate page corresponding to the guest kernel page.

9. The apparatus of claim 7 , wherein the processor is further configured to,

if the page fault is a data page fault,

fix the page fault, and

mark a page table entry corresponding to the guest kernel page as non-executable and writeable.

10. The apparatus of claim 7 , wherein the processor is further configured to, if the page fault is the instruction page fault, mark a page table entry corresponding to the guest kernel page as read-only.

11. The apparatus of claim 7 , wherein the processor is further configured to mark a page table entry of the guest kernel page as NOT_PRESENT in a shadow page table of the hypervisor.

12. Logic encoded in non-transitory media that includes code for execution and, when executed by a processor, is operable to perform operations comprising:

creating a soft whitelist having an entry corresponding to a guest kernel page of a guest OS in a hypervisor environment comprising a hypervisor, wherein the entry is a duplicate page of the guest kernel page;

mapping a virtual base address of the guest kernel page to a machine page frame number of the corresponding duplicate page, wherein the guest OS has not loaded at least some kernel components;

generating a page fault when a process attempts to access the guest kernel page; and

redirecting the process to the duplicate page corresponding to the guest kernel page if the page fault is an instruction page fault.

13. The logic of claim 12 , wherein the redirecting comprises changing a machine page frame number in a shadow page table of the hypervisor to point to the duplicate page corresponding to the guest kernel page.

14. The logic of claim 12 , the operations further comprising:

if the page fault is a data page fault:

fixing the page fault; and

marking a page table entry corresponding to the guest kernel page as non-executable and writeable.

15. The logic of claim 12 , the operations further comprising:

if the page fault is the instruction page fault, marking a page table entry corresponding to the guest kernel page as read-only.

16. The logic of claim 12 , the operations further comprising:

marking a page table entry of the guest kernel page as NOT_PRESENT in a shadow page table of the hypervisor.

17. The logic of claim 12 , the operations further comprising:

setting a lockdown feature bit in the hypervisor during a domain creation to enable rootkit protection.

18. A method, comprising:

creating a soft whitelist having an entry corresponding to a guest kernel page of a guest operating system (OS) in a hypervisor environment comprising a hypervisor, wherein the entry is a duplicate page of the guest kernel page, and the creating the soft whitelist is performed after the guest OS has loaded kernel components at boot;

walking a shadow page table of the hypervisor;

mapping a virtual address of the guest kernel page to a machine page frame number of the corresponding duplicate page;

generating a page fault when a process attempts to access the guest kernel page; and

redirecting the process to the duplicate page corresponding to the guest kernel page if the page fault is an instruction page fault.

19. Logic encoded in non-transitory media that includes code for execution and, when executed by a processor, is operable to perform operations comprising:

creating a soft whitelist having an entry corresponding to a guest kernel page of a guest OS in a hypervisor environment comprising a hypervisor, wherein the entry is a duplicate page of the guest kernel page, and the creating soft whitelist is performed after the guest OS has loaded a plurality of kernel components at boot;

walking a shadow page table of the hypervisor;

mapping a virtual address of the guest kernel page to a machine page frame number of the corresponding duplicate page;

generating a page fault when a process attempts to access the guest kernel page; and

redirecting the process to the duplicate page corresponding to the guest kernel page if the page fault is an instruction page fault.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2011
From: DANG, AMIT; MOHINDER, PREET; SRIVASTAVA, VIVEK
To: MCAFEE, INC.
Reel/Frame 027058/0682 →