IP Library Granted Patent US 9,576,129
Granted Patent B2
US 9,576,129 · App. 14/839,594 · Granted Feb 21, 2017

Defensive techniques to increase computer security

Inventor: Eric R. Northup (Seattle, WA)
Assignee: Google Inc.
G06F21/56G06F9/545G06F21/45G06F21/52G06F21/57G06F21/71G06F21/74
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,576,129
App. No.
14/839,594
Granted
Feb 21, 2017
Kind
B2
Abstract

Among other disclosed subject matter, a computer-implemented method includes changing access permission level associated with a descriptor table responsive to request to update the descriptor table. In some implementation, before receiving the request to update, the descriptor table is maintained in a read-only state; and changing the access permission level comprises: allowing write access to the descriptor table responsive to determining that the update request is authorized.

Claims (47)

1. A method comprising:

setting, by an operating system kernel, an access permission level of a descriptor table to a first permission level;

receiving, from a function by the operating system kernel, a request to update the descriptor table;

in response to receiving the request to update the descriptor table, determining, by the operating system kernel, whether the function is an operating system function or a function for another application;

determining, by the operating system kernel, that the function is an operating system function, wherein the operating system kernel is different from the operating system function;

in response to determining that the function is an operating system function, changing, by the operating system kernel, the access permission level of the descriptor table to a second permission level different than the first permission level;

updating, by the operating system kernel, the descriptor table while the access permission level of the descriptor table is the second permission level; and

after updating the descriptor table, changing, by the operating system kernel, the access permission level of the descriptor table to the first permission level.

2. The method of claim 1 , further comprising:

before receiving the request to update the descriptor table, maintaining the descriptor table in a read-only state in the first permission level.

3. The method of claim 1 , further comprising:

initializing the descriptor table using an operating system kernel.

4. The method of claim 1 , wherein setting the access permission level of the descriptor table to the first permission level comprises setting an access permission level of an interrupt descriptor table to the first permission level.

5. The method of claim 1 , wherein setting the access permission level of the descriptor table to the first permission level comprises setting an access permission level of a global descriptor table to the first permission level.

6. The method of claim 1 , wherein determining that the function is an operating system function comprises determining that the function is a hardware manager of the operating system.

7. A computing system comprising:

one or more computers; and

one or more storage units storing instructions that when executed by the one or more computers cause the one or more computers to perform operations comprising:

setting, by an operating system kernel for one of the computers, an access permission level of a descriptor table to a first permission level;

receiving, from a function by the operating system kernel, a request to update the descriptor table;

in response to receiving the request to update the descriptor table, determining, by the operating system kernel, whether the function is an operating system function or a function for another application;

determining, by the operating system kernel, that the function is an operating system function, wherein the operating system kernel is different from the operating system function;

in response to determining that the function is an operating system function, changing, by the operating system kernel, the access permission level of the descriptor table to a second permission level different than the first permission level;

updating, by the operating system kernel, the descriptor table while the access permission level of the descriptor table is the second permission level; and

after updating the descriptor table, changing, by the operating system kernel, the access permission level of the descriptor table to the first permission level.

8. The system of claim 7 , the operations further comprising:

before receiving the request to update the descriptor table, maintaining the descriptor table in a read-only state in the first permission level.

9. The system of claim 7 , the operations further comprising:

initializing the descriptor table using an operating system kernel.

10. The system of claim 7 , wherein setting the access permission level of the descriptor table to the first permission level comprises setting an access permission level of an interrupt descriptor table to the first permission level.

11. The system of claim 7 , wherein setting the access permission level of the descriptor table to the first permission level comprises setting an access permission level of a global descriptor table to the first permission level.

12. The system of claim 7 , wherein determining that the function is an operating system function comprises determining that the function is a hardware manager of the operating system.

13. A non-transitory computer storage medium encoded with a computer program, the computer program comprising instructions that when executed by a computing system cause the computing system to perform operations comprising:

setting, by an operating system kernel, an access permission level of a descriptor table to a first permission level;

receiving, from a function by the operating system kernel, a request to update the descriptor table;

in response to receiving the request to update the descriptor table, determining, by the operating system kernel, whether the function is an operating system function or a function for another application;

determining, by the operating system kernel, that the function is an operating system function, wherein the operating system kernel is different from the operating system function;

in response to determining that the function is an operating system function, changing, by the operating system kernel, the access permission level of the descriptor table to a second permission level different than the first permission level;

updating, by the operating system kernel, the descriptor table while the access permission level of the descriptor table is the second permission level; and

after updating the descriptor table, changing, by the operating system kernel, the access permission level of the descriptor table to the first permission level.

14. The non-transitory computer storage medium of claim 13 , further comprising:

before receiving the request to update the descriptor table, maintaining the descriptor table in a read-only state in the first permission level.

15. The non-transitory computer storage medium of claim 13 , further comprising:

initializing the descriptor table using an operating system kernel.

16. The non-transitory computer storage medium of claim 13 , wherein setting the access permission level of the descriptor table to the first permission level comprises setting an access permission level of an interrupt descriptor table to the first permission level.

17. The non-transitory computer storage medium of claim 13 , wherein setting the access permission level of the descriptor table to the first permission level comprises setting an access permission level of a global descriptor table to the first permission level.

18. The non-transitory computer storage medium of claim 13 , wherein determining that the function is an operating system function comprises determining that the function is a hardware manager of the operating system.

Assignments (2)
CHANGE OF NAME Recorded Oct 2, 2017
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 044097/0658 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 28, 2015
From: NORTHUP, ERIC R.
To: GOOGLE INC.
Reel/Frame 036453/0143 →
Continuity (3)
Continuation 14473085 · Aug 29, 2014
Division 13277063 · Oct 19, 2011
Related Publication 20150371041A1 · Dec 24, 2015