IP Library Granted Patent US 11,886,350
Granted Patent B2
US 11,886,350 · App. 17/034,035 · Granted Jan 30, 2024

System memory context determination for integrity monitoring and related techniques

Inventor: Nathan T. Palmer (Austin, TX)
Assignee: Raytheon Company
G06F12/1009G06F9/4406G06F9/45558G06F11/3037G06F12/0882G06F12/1408G06F2009/45583G06F2009/45591
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,886,350
App. No.
17/034,035
Granted
Jan 30, 2024
Kind
B2
Abstract

Techniques are disclosed for context-aware monitoring of the system memory to provide system integrity. An example methodology implementing the techniques includes determining a type of operating system (OS) that is loaded on system memory, examining contents of at least one system memory page, and assigning at least one tag to the at least one system memory page based on the determined type of OS and the examination of the contents of the at least one system memory page. The at least one tag indicates the characteristics of the contents of the at least one system memory page.

Claims (31)

1. A computer-implemented method comprising:

determining, by a hypervisor, that an operating system (OS) is started in a host virtualization system, wherein the started OS comprises a boot fingerprint comprising an allocation of one or more host physical memory (HPM) pages;

examining, by the hypervisor, contents of at least one system memory page of the one or more HPM pages to determine a type of OS that is loaded on the at least one system memory page of the one or more HPM pages, wherein the examination comprises analyzing information loaded on the one or more HPM pages when the OS is started and based on the boot fingerprint, wherein the boot fingerprint identifies various operating systems based on the one or more HPM pages storing particular aspects of the OS in specific addresses; and

assigning, by the hypervisor and subsequent to the examination, at least one tag to the at least one system memory page of the one or more HPM pages based on the determined type of OS and the examination of the contents of the at least one system memory page of the one or more HPM pages,

wherein the at least one tag indicates characteristics of the contents stored in the at least one system memory page of the one or more HPM pages including characteristics of data stored in an extended page table (EPT), and wherein the at least one tag allows for context-aware monitoring of the at least one system memory page.

2. The computer-implemented method of claim 1 , wherein the at least one tag indicates a type of data stored in the at least one system memory page.

3. The computer-implemented method of claim 1 , wherein the at least one tag indicates that the at least one system memory page is a critical system memory page.

4. The computer-implemented method of claim 3 , further comprising:

hashing the contents of the at least one system memory page to compute a hash value; and

comparing the computed hash value to a corresponding golden hash value to determine the integrity of the least one system memory page.

5. A system comprising:

one or more non-transitory machine-readable mediums configured to store instructions; and

one or more processors configured to execute the instructions stored on the one or more non-transitory machine-readable mediums, wherein execution of the instructions causes the one or more processors to:

determine, by a hypervisor, that an operating system (OS) is started in a host virtualization system, wherein the started OS comprises a boot fingerprint comprising an allocation of one or more host physical memory (HPM) pages;

examine, by the hypervisor, contents of at least one system memory page of the one or more HPM pages to determine a type of OS that is loaded on the at least one system memory page of the one or more HPM pages, wherein the examination comprises analyzing information loaded on the one or more HPM pages when the OS is started and based on the boot fingerprint, wherein the boot fingerprint identifies various operating systems based on the one or more HPM pages storing particular aspects of the OS in specific addresses; and

assign, by the hypervisor and subsequent to the examination, at least one tag to the at least one system memory page of the one or more HPM pages based on the determined type of OS and the examination of the contents of the at least one system memory page of the one or more HPM pages, wherein the at least one tag indicates characteristics of the contents stored in the at least one system memory page of the one or more HPM pages including characteristics of data stored in an extended page table (EPT), and wherein the at least one tag allows for context-aware monitoring of the at least one system memory page.

6. The system of claim 5 , wherein the at least one tag indicates a type of data stored in the at least one system memory page.

7. The system of claim 5 , wherein the at least one tag indicates that the at least one system memory page is a critical system memory page.

8. The system of claim 7 , wherein execution of the instructions causes the one or more processors to:

hash the contents of the at least one system memory page to compute a hash value; and

compare the computed hash value to a corresponding golden hash value to determine the integrity of the least one system memory page.

9. A computer program product including one or more non-transitory machine readable mediums encoded with instructions that when executed by one or more processors cause a process to be carried out, the process comprising:

determining, by a hypervisor, that an operating system (OS) is started in a host virtualization system, wherein the started OS comprises a boot fingerprint comprising an allocation of one or more host physical memory (HPM) pages;

examining, by the hypervisor, contents of at least one system memory page of the one or more HPM pages to determine a type of OS that is loaded on the at least one system memory page of the one or more HPM pages, wherein the examination comprises analyzing information loaded on the one or more HPM pages when the OS is started and based on the boot fingerprint, wherein the boot fingerprint identifies various operating systems based on the one or more HPM pages storing particular aspects of the OS in specific addresses; and

assigning, by the hypervisor and subsequent to the examination, at least one tag to the at least one system memory page of the one or more HPM pages based on the determined type of OS and the examination of the contents of the at least one system memory page of the one or more HPM pages,

wherein the at least one tag indicates characteristics of the contents stored in the at least one system memory page of the one or more HPM pages including characteristics of data stored in an extended page table (EPT), and wherein the at least one tag allows for context-aware monitoring of the at least one system memory page.

10. The computer program product of claim 9 , wherein the at least one tag indicates a type of data stored in the at least one system memory page.

11. The computer program product of claim 9 , wherein the at least one tag indicates that the at least one system memory page is a critical system memory page.

12. The computer program product of claim 11 , the process further comprising:

hashing the contents of the at least one system memory page to compute a hash value; and

comparing the computed hash value to a corresponding golden hash value to determine the integrity of the least one system memory page.

Assignments (4)
CHANGE OF NAME Recorded Jul 3, 2024
From: COLUMBUS BUYER LLC
To: NIGHTWING GROUP, LLC
Reel/Frame 068106/0251 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2024
From: RAYTHEON COMPANY
To: COLUMBUS BUYER LLC
Reel/Frame 068233/0420 →
SECURITY INTEREST Recorded Apr 1, 2024
From: COLUMBUS BUYER LLC; RAYTHEON BLACKBIRD TECHNOLOGIES, INC.; RAYTHEON FOREGROUND SECURITY, INC.
To: WELLS FARGO BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066960/0411 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2020
From: PALMER, NATHAN T.
To: RAYTHEON COMPANY
Reel/Frame 053897/0683 →