IP Library Granted Patent US 10,810,309
Granted Patent B2
US 10,810,309 · App. 16/571,341 · Granted Oct 20, 2020

Method and system for detecting kernel corruption exploits

Inventors: Dani Frank (Maale Adomim, IL); Yoav Alon (Tel Aviv, IL); Aviv Gafni (Ramat Gan, IL); Ben Omelchenko (Tel Aviv, IL)
Assignee: Check Point Advanced Threat Prevention Ltd
G06F21/554G06F9/45558G06F9/4843G06F21/52G06F21/562G06F21/577G06F2009/45587G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,810,309
App. No.
16/571,341
Granted
Oct 20, 2020
Kind
B2
Abstract

Methods and systems provide for detecting exploitation of kernel vulnerabilities which typically corrupt memory. The methods and systems are implemented, for example, via a host, which includes a hypervisor, which controls the operating system (OS) user space and the OS kernel space.

Claims (7)

1. A computerized method for mitigating exploitation of kernel vulnerabilities, comprising:

providing a host to a memory system, the memory system comprising a guest user space and a guest kernel space; and,

the host responsive to attempts to exploit a Central Processing unit (CPU) security feature from the guest user space, the host controlling the logic for the guest kernel space, upon receiving an indication of an attempt to exploit the CPU security feature, the host controlling the logic includes: 1) rendering the guest kernel space transparent to exploitation attempts to the guest user space, and, 2) the host sending a false value to the memory system, causing the SMEP bit to remain enabled, and, the CPU security feature including an SMEP (Supervisor Mode Execution Protection/Prevention) bit of a CR4 register, and, the attempt to exploit the CPU security feature including the SMEP bit includes an attempt to change a value in the CR4 register.

2. The computerized method of claim 1 , additionally comprising: detecting an exploit at the guest user space which defines an indication of an attempt to exploit the CPU security feature, and, the host controlling the guest kernel space to enable the protection system associated with the guest kernel space.

3. The computerized method of claim 1 , wherein the attempt to change a value in the CR4 register includes an attempt to READ or WRITE in the CR4 register.

4. The computerized method of claim 1 , wherein upon receiving the indication of the attempt to exploit the SMEP bit, the host reports the attempt to exploit the SMEP bit as a security violation.

5. The computerized method of claim 4 , wherein the host includes a hypervisor.

Assignments (1)
MERGER Recorded Sep 11, 2024
From: CHECK POINT ADVANCED THREAT PREVENTION LTD
To: CHECK POINT SOFTWARE TECHNOLOGIES LTD.
Reel/Frame 068548/0794 →
Continuity (2)
Continuation 15473654 · Mar 30, 2017
Related Publication 20200012787A1 · Jan 9, 2020