IP Library Granted Patent US 8,826,440
Granted Patent B2
US 8,826,440 · App. 13/277,063 · Granted Sep 2, 2014

Defensive techniques to increase computer security

Inventor: Eric R. Northup (Seattle, WA)
Assignee: Google Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,826,440
App. No.
13/277,063
Granted
Sep 2, 2014
Kind
B2
Abstract

Among other disclosed subject matter, a computer-implemented method includes initializing a first descriptor table and a second descriptor table. The first descriptor table is associated with a first permission level and the second descriptor table is associated with a second permission level that is different from the first permission level. The first descriptor table and the second descriptor table are associated with a hardware processor and initialized by an operating system kernel. The method also includes providing a memory address associated with the first descriptor table, in response to a descriptor table address request. The descriptor table address request is provided by a software process. The method also includes updating the second descriptor table, in response to an update request.

Claims (38)

1. A computer-implemented method, the method comprising:

initializing a first descriptor table associated with a first permission level;

generating a random location for a second descriptor table, wherein the random location is a location that is not determinable by user mode software processes using commands associated with a hardware processor

initializing the second descriptor table at the random location, wherein the second descriptor table is associated with a second permission level that is different from the first permission level, the first descriptor table and the second descriptor table are associated with the hardware processor and initialized by an operating system kernel, the first permission level is read only and the second permission level is read write;

in response to a descriptor table address request, providing a memory address associated with the first descriptor table, wherein the descriptor table address request is provided by at least one user mode software process; and

in response to an update request for the first descriptor table by the at least one user mode software process, updating the second descriptor table responsive to the operating system kernel determining that the update request is valid and trusted, wherein the location of the second descriptor table is not revealed to the at least one user mode software process.

2. The computer-implemented method of claim 1 wherein updating the second descriptor table causes the first descriptor table to be updated.

3. The computer-implemented method of claim 1 wherein the first descriptor table and the second descriptor table comprise interrupt descriptor tables.

4. The computer-implemented method of claim 1 wherein the first descriptor table and the second descriptor table comprise global descriptor tables.

5. The computer-implemented method of claim 1 wherein the descriptor table address request comprises a store global descriptor table instruction or a store interrupt descriptor table instruction.

6. The computer-implemented method of claim 1 wherein data included in the first descriptor table is equal to data included in the second descriptor table.

7. The computer-implemented method of claim 1 wherein the software process comprises malware or a computer virus.

8. A non-transitory, computer-readable medium storing instructions operable when executed to cause a hardware processor to perform operations comprising:

initializing a first descriptor table associated with a first permission level;

generating a random location for a second descriptor table, wherein the random location is a location that is not determinable by user mode software processes using commands associated with the hardware processor;

initializing the second descriptor table at the random location, wherein the second descriptor table is associated with a second permission level that is different from the first permission level, the first descriptor table and the second descriptor table are associated with the hardware processor and initialized by an operating system kernel, the first permission level is read only and the second permission level is read write;

in response to a descriptor table address request, providing a memory address associated with the first descriptor table, wherein the descriptor table address request is provided by at least one user mode software process; and

in response to an update request for the first descriptor table by the at least one user mode software process, updating the second descriptor table responsive to the operating system kernel determining that the update request is valid and trusted, wherein the location of the second descriptor table is not revealed to the at least one user mode software process.

9. The computer-readable medium of claim 8 wherein updating the second descriptor table causes the first descriptor table to be updated.

10. The computer-readable medium of claim 8 wherein the first descriptor table and the second descriptor table comprise interrupt descriptor tables.

11. The computer-readable medium of claim 8 wherein the first descriptor table and the second descriptor table comprise global descriptor tables.

12. The computer-readable medium of claim 8 wherein the descriptor table address request comprises a store global descriptor table instruction or a store interrupt descriptor table instruction.

13. The computer-readable medium of claim 8 wherein data included in the first descriptor table is equal to data included in the second descriptor table.

14. The computer-readable medium of claim 8 wherein the software process comprises malware or a computer virus.

15. A system comprising:

memory for storing data; and

one or more hardware processors operable to perform operations comprising:

initializing a first descriptor table associated with a first permission level;

generating a random location for a second descriptor table, wherein the random location is a location that is not determinable by user mode software processes using commands associated with the one or more hardware processors;

initializing the second descriptor table at the random location, wherein the second descriptor table is associated with a second permission level that is different from the first permission level, the first descriptor table and the second descriptor table are associated with the one or more hardware processors and initialized by an operating system kernel, the first permission level is read only and the second permission level is read write;

in response to a descriptor table address request, providing a memory address associated with the first descriptor table, wherein the descriptor table address request is provided by at least one user mode software process; and

in response to an update request for the first descriptor table by the at least one user mode software process, updating the second descriptor table responsive to the operating system kernel determining that the update request is valid and trusted, wherein the location of the second descriptor table is not revealed to the at least one user mode software process.

16. The system of claim 15 wherein updating the second descriptor table causes the first descriptor table to be updated.

17. The system of claim 15 wherein the first descriptor table and the second descriptor table comprise interrupt descriptor tables.

18. The system of claim 15 wherein the first descriptor table and the second descriptor table comprise global descriptor tables.

19. The system of claim 15 wherein the descriptor table address request comprises a store global descriptor table instruction or a store interrupt descriptor table instruction.

20. The system of claim 15 wherein data included in the first descriptor table is equal to data included in the second descriptor table.

21. The system of claim 15 wherein the software process comprises malware or a computer virus.

Assignments (2)
CHANGE OF NAME Recorded Oct 2, 2017
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 044277/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 8, 2012
From: NORTHUP, ERIC R.
To: GOOGLE INC.
Reel/Frame 028173/0030 →
Continuity (1)
Related Publication 20130104234A1 · Apr 25, 2013