IP Library Granted Patent US 11,409,635
Granted Patent B2
US 11,409,635 · App. 16/550,056 · Granted Aug 9, 2022

Hacker-resistant anti-debug system

Inventor: Daniel S. Rose (Salado, TX)
Assignee: Raytheon Company
G06F11/3656G06F11/3096G06F12/0253G06F21/14G06F2009/45591
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,409,635
App. No.
16/550,056
Granted
Aug 9, 2022
Kind
B2
Abstract

A computer system includes an operating system, a memory coupled to the operating system, and a processor (e.g., an anti-debug processor) coupled to the operating system. The operating system receives, from a debug process, a request to create an essential debug object for attachment to a target process. The anti-debug processor scans a kernel memory of the operating system for the essential debug object and verifies a presence of the essential debug object in the kernel memory, and scans the kernel memory to identify a process that has stored in the kernel memory the essential debug object. The anti-debug processor then halts the debug process, without using an internal interface or function of the operating system, thereby preventing the debug process from attaching to the target process.

Claims (40)

1. A process comprising:

receiving, into a computer processor, an identification of essential objects used by an operating system, a target program, or a debug program to enable the debug program to attach to and debug the target program;

receiving, into the computer processor, information regarding use of the essential objects by the operating system, the target program, and the debug program;

monitoring the operating system, the target program, and the debug program to identify an instantiation of one or more of the essential objects; and

halting execution of the debug program via the essential objects, and without using an internal interface of the operating system or a function of the operating system, based on one or more of the identification of the essential objects, the information regarding the use of the essential objects, and the identification of the instantiation of the one or more of the essential objects.

2. The process of claim 1 , wherein the essential objects comprise essential kernel objects without which the target program or the debug program can execute.

3. The process of claim 2 , wherein the essential kernel objects are not associated with documentation of the operating system.

4. The process of claim 2 , wherein the essential kernel objects comprise kernel memory flags and inter-process communication objects.

5. The process of claim 1 , wherein the information regarding the use of the essential objects by the operating system, the target program, and the debug program comprises a structure of the essential objects in a memory and a location of the essential objects in the memory.

6. The process of claim 1 , further comprising identifying a process that invokes the debug program by searching a memory associated with the process for the one or more of the essential objects.

7. The process of claim 1 , further comprising:

identifying a variable in a memory of the target program that hides a program event from the debug program; and

setting a value for the variable in the memory of the target program.

8. The process of claim 1 , further comprising providing information to the essential objects such that it appears that the debug program is executing even though the debug program has been halted or the debug program is not executing.

9. The process of claim 1 , wherein the essential objects halt execution of the debug program or hinder execution of the debug program.

10. The process of claim 1 , wherein the debug program is resident on the computer processor or the debug program is imported into the computer processor by an external process.

11. The process of claim 1 , wherein the identification of the essential objects used by the operating system, the target program, or the debug program is determined by a reverse engineering process.

12. The process of claim 1 , wherein the monitoring the operating system, the target program, and the debug program to identify the instantiation of the one or more of the essential objects comprises:

scanning a kernel memory of the operating system for the essential objects and verifying a presence of the essential objects in the kernel memory; and

scanning the kernel memory to identify a process that has stored the essential objects in the kernel memory.

13. A process comprising:

receiving, from a debug process, into an anti-debug processor in an operating system, a request to create an essential debug object for attachment to a target process;

scanning, via the anti-debug processor, a kernel memory of the operating system for the essential debug object and verifying a presence of the essential debug object in the kernel memory of the operating system;

scanning, via the anti-debug processor, the kernel memory of the operating system to identify a process that has stored in the kernel memory of the operating system the essential debug object; and

halting the debug process in the operating system, via the anti-debug processor without using an internal interface of the operating system or a function of the operating system, thereby preventing the debug process in the operating system from attaching to the target process.

14. The process of claim 13 , wherein the essential debug object is not associated with documentation of the operating system.

15. The process of claim 13 , wherein the essential debug object halts execution of the debug process in the operating system or hinders execution of the debug process in the operating system.

16. The process of claim 13 , further comprising identifying a process that invokes the debug process in the operating system by searching a memory associated with the process for the essential debug object.

17. The process of claim 13 , wherein an identification of the essential debug object is determined by a reverse engineering process.

18. The process of claim 13 , comprising providing information to the essential debug object such that it appears that the debug process in the operating system is executing even though the debug process in the operating system has been halted or the debug process in the operating system is not executing.

19. A computer system comprising:

an operating system;

a memory coupled to the operating system; and

an anti-debug processor coupled to the operating system;

wherein the anti-debug processor is operable to:

receive, from a debug process, in the operating system, a request to create an essential debug object for attachment to a target process;

scan a kernel memory of the operating system for the essential debug object and verify a presence of the essential debug object in the kernel memory of the operating system;

scan the kernel memory of the operating system to identify a process that has stored in the kernel memory of the operating system the essential debug object; and

halt the debug process in the operating system, without using an internal interface of the operating system or a function of the operating system, thereby preventing the debug process in the operating system from attaching to the target process.

20. The computer system of claim 19 , wherein the anti-debug processor is further operable to provide information to the essential debug object such that it appears that the debug process in the operating system is executing even though the debug process in the operating system has been halted or the debug process in the operating system is not executing.

Assignments (4)
CHANGE OF NAME Recorded Jul 3, 2024
From: COLUMBUS BUYER LLC
To: NIGHTWING GROUP, LLC
Reel/Frame 068106/0251 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2024
From: RAYTHEON COMPANY
To: COLUMBUS BUYER LLC
Reel/Frame 068233/0420 →
SECURITY INTEREST Recorded Apr 1, 2024
From: COLUMBUS BUYER LLC; RAYTHEON BLACKBIRD TECHNOLOGIES, INC.; RAYTHEON FOREGROUND SECURITY, INC.
To: WELLS FARGO BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066960/0411 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2019
From: ROSE, DANIEL S.
To: RAYTHEON COMPANY
Reel/Frame 050154/0681 →