IP Library Granted Patent US 10,467,407
Granted Patent B2
US 10,467,407 · App. 15/473,654 · Granted Nov 5, 2019

Method and system for detecting kernel corruption exploits

Inventors: Dani Frank (Maale Adomim, IL); Yoav Alon (Tel Aviv, IL); Aviv Gafni (Ramat Gan, IL); Ben Omelchenko (Tel Aviv, IL)
Assignee: Check Point Advanced Threat Prevention Ltd.
G06F21/554G06F9/45558G06F9/4843G06F21/52G06F21/562G06F21/577G06F2009/45587G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,467,407
App. No.
15/473,654
Granted
Nov 5, 2019
Kind
B2
Abstract

Methods and systems provide for detecting exploitation of kernel vulnerabilities which typically corrupt memory. The methods and systems are implemented, for example, via a host, which includes a hypervisor, which controls the operating system (OS) user space and the OS kernel space.

Claims (12)

1. A computerized method for detecting attempts of code execution from memory pages from non-executable memory in a Kernel Space, comprising:

providing a host for a memory system, the memory system comprising a guest user space and a guest kernel space, the host managing a branches buffer for each process operating in the memory system;

writing, by the host, a shadow page table entry (SPTE) for a memory page, the shadow page table entry describing a guest address;

determining that the guest address is a kernel mode address;

determining whether the kernel mode address is an executable kernel address; and,

if the kernel mode address is an executable kernel address, disable a NX bit in the SPTE, so that the code executes; and,

if the kernel mode address is not an executable kernel address, enable the NX bit in the SPTE, so that the code is non-executable.

2. The computerized method of claim 1 , wherein the determining whether the kernel mode address is an executable kernel address is performed by checking the kernel mode address against addresses in a white list.

3. The computerized method of claim 1 , additionally comprising:

when the NX bit in the SPTE has been enabled, determining whether the kernel mode address is a kernel address, and if the kernel mode address is a kernel address which is not a predetermined address, report the kernel mode address as malicious or potentially malicious.

4. The computerized method of claim 3 , wherein predetermined address is provided in a white list.

5. The computerized method of claim 1 , wherein the host includes a hypervisor.

Assignments (1)
MERGER Recorded Sep 11, 2024
From: CHECK POINT ADVANCED THREAT PREVENTION LTD
To: CHECK POINT SOFTWARE TECHNOLOGIES LTD.
Reel/Frame 068548/0794 →
Continuity (1)
Related Publication 20180285561A1 · Oct 4, 2018
Cited By (3)
US 12,189,780 US 12,489,763 US 12,500,905