IP Library Granted Patent US 9,703,957
Granted Patent B2
US 9,703,957 · App. 15/377,649 · Granted Jul 11, 2017

Atomic detection and repair of kernel memory

Inventor: Ahmed Said Sallam (Cupertino, CA)
Assignee: McAfee, Inc.
G06F21/564G06F9/442G06F21/56G06F21/566G06F21/568H04L63/145H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,703,957
App. No.
15/377,649
Granted
Jul 11, 2017
Kind
B2
Abstract

A method for detecting memory modifications includes allocating a contiguous block of a memory of an electronic device, and loading instructions for detecting memory modifications into the contiguous block of memory. The electronic device includes a plurality of processing entities. The method also includes disabling all but one of a plurality of processing entities of the electronic device, scanning the memory of the electronic device for modifications performed by malware, and, if a memory modification is detected, repairing the memory modification. The method also includes enabling the processing entities that were disabled. The remaining processing entity executes the instructions for detecting memory modifications.

Claims (52)

1. A method for detecting memory modifications, comprising:

allocating a contiguous block of a memory of an electronic device, the electronic device comprising a plurality of processing cores;

loading instructions for detecting memory modifications into the contiguous block of memory;

disabling the operation of an operating system of the electronic device by disabling one or more of system interrupts, user interrupts, or scheduler timer interrupts;

disabling all but one of the plurality of processing cores of the electronic device, the remaining processing core executing the instructions for detecting memory modifications;

scanning the memory of the electronic device for modifications performed by malware, after disabling all but one of the plurality of processing cores and disabling one or more of system interrupts, user interrupts, or scheduler timer interrupts;

enabling the one or more of the system interrupts, user interrupts, or scheduler timer interrupts that were disabled, after scanning the memory of the electronic device for modifications; and

enabling the processing cores that were disabled, after scanning the memory of the electronic device for modifications.

2. The method of claim 1 , wherein:

loading instructions for detecting memory modifications into the contiguous block of memory comprises loading the entirety of the instructions within the contiguous block; and

disabling all but one of the plurality of processing cores of the electronic device, the remaining processing core executing the instructions for detecting memory modifications comprises executing the instructions as resident within the contiguous block.

3. The method of claim 1 , further comprising repairing a memory modification detected during scanning the memory of the electronic device for modifications performed by malware, before enabling the one or more system interrupts, user interrupts, or scheduler timer interrupts that were disabled.

4. The method of claim 1 , wherein the memory modifications comprise modifications to kernel memory.

5. The method of claim 1 , wherein the memory modifications comprise modifications to application memory.

6. The method of claim 1 , wherein the contiguous block of memory is allocated in non-pageable memory.

7. The method of claim 1 , further comprising, before disabling all but one of the plurality of processing cores of the electronic device, modifying an affinity associated with the loaded instructions to one of the plurality of processing cores of the electronic device, wherein the processing core is the remaining processing core for executing the instructions for detecting memory modifications.

8. The method of claim 1 , further comprising:

subsequent to disabling the operating system, enabling the operating system to access a system function, the system function used for repair or diagnosis of memory; and

subsequently disabling the operating system after utilizing the system function.

9. The method of claim 1 , wherein the processing cores of the electronic device are shut down using an operating system service.

10. The method of claim 1 , further comprising:

detecting a memory modification during scanning of the memory of the electronic device;

enabling a system resource, wherein the system resource is the one or more disabled processing cores, or the one or more disabled system interrupts, user interrupts, or scheduler timer interrupts;

in response to detecting a memory modification, repairing the memory modification; and

disabling the system resource after repairing the memory modification.

11. An article of manufacture, comprising:

a non-transitory computer readable medium; and

computer-executable instructions carried on the non-transitory computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to:

allocate a contiguous block of a memory of an electronic device, the electronic device comprising a plurality of processing cores;

load instructions for detecting memory modifications into the contiguous block of memory;

disable the operation of an operating system of the electronic device by disabling one or more of system interrupts, user interrupts, or scheduler timer interrupts;

disable all but one processing cores of the electronic device, the remaining processing core for executing the instructions for detecting memory modifications;

scan the memory of an electronic device for modifications performed by malware, after all but one of the plurality of processing cores is disabled and one or more of system interrupts, user interrupts, or scheduler timer interrupts is disabled;

enable the one or more of system interrupts, user interrupts, or scheduler timer interrupts that were disabled, after the scan of the memory of the electronic device for modifications; and

enable the processing cores that were disabled, after the scan of the memory of the electronic device for modifications.

12. The article of claim 11 , wherein:

the entirety of the instructions for detecting memory modifications are loaded within the contiguous block; and

the instructions for detecting memory modifications that are executed by the remaining processing core are resident within the contiguous block.

13. The article of claim 11 , wherein the processing is further caused to repair a memory modification detected during the scan of the memory of the electronic device for modifications performed by malware, before the one or more disabled system interrupts, user interrupts, or scheduler timer interrupts is enabled.

14. The article of claim 11 , wherein the memory modifications comprise modifications to kernel memory.

15. The article of claim 11 , wherein the memory modifications comprise modifications to application memory.

16. The article of claim 11 , wherein the contiguous block of memory is allocated in non-pageable memory.

17. The article of claim 11 , wherein the processing is further caused to, before all but one of the plurality of processing cores of the electronic device are disabled, modify an affinity associated with the loaded instructions to one of the plurality of processing cores of the electronic device, wherein the processing core is the remaining processing core for executing the instructions for detecting memory modifications.

18. The article of claim 11 , wherein the processing is further caused to:

subsequent to disabling the operating system, enable the operating system to access a system function, the system function used for repair or diagnosis of memory; and

subsequently disable the operating system after utilizing the system function.

19. The article of claim 11 , wherein the processing cores of the electronic device are caused to be shut down using an operating system service.

20. The article of claim 11 , wherein the processing is further caused to:

detect a memory modification during the scan of the memory of the electronic device;

enable a system resource, wherein the system resource is the one or more disabled processing cores, or the one or more disabled system interrupts, user interrupts, or scheduler timer interrupts;

in response to detection of a memory modification, repair the memory modification; and

disable the system resource after the memory modification is repaired.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 13, 2016
From: SALLAM, AHMED SAID
To: MCAFEE, INC.
Reel/Frame 040727/0322 →
Continuity (2)
Continuation 12874700 · Sep 2, 2010
Related Publication 20170091452A1 · Mar 30, 2017