IP Library Patent Application 17113195
Patent Application
App. No. 17/113,195

SYSTEMS AND METHODS FOR PROTECTING AGAINST UNAUTHORIZED MEMORY DUMP MODIFICATION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/113,195
Abstract

Disclosed herein are systems and methods for protecting against unauthorized memory dump modification. In an exemplary aspect, a method may comprise producing a memory dump of a computing device, and identifying a current kernel function used for producing the memory dump. In response to determining that the current kernel function is not authorized to produce the memory dump, the method may comprise determining that the produced memory dump has been modified, analyzing a call tree to identify an original kernel function authorized to produce memory dumps, and calling the original kernel function to produce an authentic memory dump.

Claims (46)

1 . A method for protecting against unauthorized memory dump modification, the method comprising:

producing a memory dump of a computing device;

identifying a current kernel function used for producing the memory dump;

in response to determining that the current kernel function is not authorized to produce the memory dump:

determining that the produced memory dump has been modified;

analyzing a call tree to identify an original kernel function authorized to produce memory dumps; and

calling the original kernel function to produce an authentic memory dump.

2 . The method of claim 1 , wherein determining that the current kernel function is not authorized to produce the memory dump comprises determining that an entry, in a dispatch table, that points to a kernel function for memory dumping has been modified.

3 . The method of claim 2 , wherein determining that the entry has been modified comprises determining that an address associated with a system call number in the dispatch table at first time does not match an address associated with the system call number at a second time.

4 . The method of claim 1 , wherein determining that the current kernel function is not authorized to produce the memory dump is based on determining that an address of the current kernel function is not in an operating system kernel range of the computing device.

5 . The method of claim 1 , wherein analyzing the call tree to identify the original kernel function comprises determining an offset indicating the original kernel function based on contents of an entry in the call tree.

6 . The method of claim 1 , wherein determining that the current kernel function is not authorized to produce the memory dump further comprises:

comparing an on-disk kernel image of the computing device with an in-memory kernel image of the computing device;

identifying modified kernel fragments used to produce the memory dump based on the comparison; and

determining that the modified kernel fragments are caused by malware.

7 . A system for protecting against unauthorized memory dump modification, the system comprising:

a hardware processor configured to:

produce a memory dump of a computing device;

identify a current kernel function used for producing the memory dump;

in response to determining that the current kernel function is not authorized to produce the memory dump:

determine that the produced memory dump has been modified;

analyze a call tree to identify an original kernel function authorized to produce memory dumps; and

call the original kernel function to produce an authentic memory dump.

8 . The system of claim 7 , the hardware processor is configured to determine that the current kernel function is not authorized to produce the memory dump by determining that an entry, in a dispatch table, that points to a kernel function for memory dumping has been modified.

9 . The system of claim 8 , the hardware processor is configured to determine that the entry has been modified by determining that an address associated with a system call number in the dispatch table at first time does not match an address associated with the system call number at a second time.

10 . The system of claim 7 , the hardware processor is configured to determine that the current kernel function is not authorized to produce the memory dump based on determining that an address of the current kernel function is not in an operating system kernel range of the computing device.

11 . The system of claim 7 , the hardware processor is configured to analyze the call tree to identify the original kernel function by determining an offset indicating the original kernel function based on contents of an entry in the call tree.

12 . The system of claim 7 , the hardware processor is configured to determine that the current kernel function is not authorized to produce the memory dump by:

comparing an on-disk kernel image of the computing device with an in-memory kernel image of the computing device;

identifying modified kernel fragments used to produce the memory dump based on the comparison; and

determining that the modified kernel fragments are caused by malware.

13 . A non-transitory computer readable medium storing thereon computer executable instructions for protecting against unauthorized memory dump modification, including instructions for:

producing a memory dump of a computing device;

identifying a current kernel function used for producing the memory dump;

in response to determining that the current kernel function is not authorized to produce the memory dump:

determining that the produced memory dump has been modified;

analyzing a call tree to identify an original kernel function authorized to produce memory dumps; and

calling the original kernel function to produce an authentic memory dump.

14 . The non-transitory computer readable medium of claim 13 , wherein instructions for determining that the current kernel function is not authorized to produce the memory dump further comprise instructions for determining that an entry, in a dispatch table, that points to a kernel function for memory dumping has been modified.

15 . The non-transitory computer readable medium of claim 14 , wherein instructions for determining that the entry has been modified further comprise instructions for determining that an address associated with a system call number in the dispatch table at first time does not match an address associated with the system call number at a second time.

16 . The non-transitory computer readable medium of claim 13 , wherein instructions for determining that the current kernel function is not authorized to produce the memory dump further comprise instructions for determining that an address of the current kernel function is not in an operating system kernel range of the computing device.

17 . The non-transitory computer readable medium of claim 13 , wherein instructions for analyzing the call tree to identify the original kernel function further comprise instructions for determining an offset indicating the original kernel function based on contents of an entry in the call tree.

18 . The non-transitory computer readable medium of claim 13 , wherein instructions for determining that the current kernel function is not authorized to produce the memory dump further comprise instructions for:

comparing an on-disk kernel image of the computing device with an in-memory kernel image of the computing device;

identifying modified kernel fragments used to produce the memory dump based on the comparison; and

determining that the modified kernel fragments are caused by malware.

Assignments (1)
REAFFIRMATION AGREEMENT Recorded Aug 28, 2022
From: ACRONIS AG; ACRONIS INTERNATIONAL GMBH; ACRONIS SCS, INC.; ACRONIS, INC.; GROUPLOGIC, INC.; NSCALED INC.; ACRONIS MANAGEMENT LLC; 5NINE SOFTWARE, INC.; ACRONIS GERMANY GMBH; ACRONIS NETHERLANDS B.V.; ACRONIS BULGARIA EOOD; DEVICELOCK, INC.; DEVLOCKCORP LTD; ACRONIS INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 061330/0818 →