IP Library › Granted Patent US 9,817,976
Granted Patent B2
US 9,817,976 · App. 14/757,945 · Granted Nov 14, 2017

Techniques for detecting malware with minimal performance degradation

Inventors: Michael Lemay (Hillsboro, OR); David M. Durham (Beaverton, OR)
Assignee: INTEL CORPORATION
G06F21/566H04L63/145H04L63/1416G06F2221/032
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,817,976
App. No.
14/757,945
Granted
Nov 14, 2017
Kind
B2
Abstract

Various embodiments are generally directed to techniques for detecting malware in a manner that mitigates the consumption of processing and/or storage resources of a processing device. An apparatus may include a first processor component of a processing device to generate entries in a chronological order within a first page modification log maintained within a first storage divided into multiple pages, each entry to indicate a write access made by the first processor component to a page of the multiple pages; a retrieval component of a graphics controller of the processing device to recurringly retrieve indications from the first page modification log of at least one recently written page of the multiple pages; and a scan component of the graphics controller to recurringly scan the at least one recently written page to detect malware within the at least one recently written page.

Claims (51)

1. An apparatus to support secure processing comprising:

a first processor component of a processing device to generate entries in a chronological order within a first page modification log maintained within a first storage divided into multiple pages, each entry to indicate a write access made by the first processor component to a page of the multiple pages;

a retrieval component of a graphics controller of the processing device to recurringly retrieve indications from the first page modification log of at least one recently written page of the multiple pages; and

a scan component of the graphics controller to recurringly scan the at least one recently written page to detect malware within the at least one recently written page.

2. The apparatus of claim 1 , the first processor component comprising an address translator to support virtual addressing based on the multiple pages and to generate each entry within the first page modification log in response to a provision of an address translation for a write access to a page of the multiple pages.

3. The apparatus of claim 2 , the address translator to walk multiple layers of page tables maintained within the first storage to translate addresses to support multiple virtual machines (VMs) generated by a host OS and to enable a guest OS that employs virtual addressing within one of the VMs to access at least a subset of the multiple pages associated with the one of the VMs by the host OS.

4. The apparatus of claim 3 , the address translator to generate the entries within multiple page modification logs, each VM associated with at least one page modification log of the multiple page modification logs, the multiple page modification logs comprising the first page modification log, and the retrieval component to recurringly retrieve indications from the multiple page modification logs of recently written pages.

5. The apparatus of claim 1 , the first storage to store a security routine executed by the first processor component to counteract malware, the scan component to provide an indication to the security routine of malware detected within a page by the scan component.

6. The apparatus of claim 5 , comprising a network interface to couple the processing device to a network, the scan component to analyze an address of a page in which the malware is detected to determine a severity associated with the malware, and to transmit an indication to a security server via the network of malware detected within a page by the scan component in lieu of provision of the indication to the security routine based on the severity.

7. An apparatus to support secure processing comprising:

a storage controller of a processing device to generate entries in a chronological order within a first page modification log maintained within a first storage coupled to the storage controller and divided into multiple pages, each entry to indicate a write access made to a page of the multiple pages;

a retrieval component of a graphics controller of the processing device to recurringly retrieve indications from the first page modification log of at least one recently written page of the multiple pages; and

a scan component of the graphics controller to recurringly scan the at least one recently written page to detect malware within the at least one recently written page.

8. The apparatus of claim 7 , the first page modification log to accommodate a limited quantity of the entries and the retrieval component to cooperate with the storage controller to generate the entries within a second page modification log maintained within the first storage to allow the retrieval component more time to retrieve indications of recently written pages from the entries within the first page modification log before the entries within the first page modification log are overwritten with new entries generated by the storage controller.

9. The apparatus of claim 8 , the storage controller to rotate among at least the first and second page modification logs to generate the entries, and the retrieval component to rotate among at least the first and second page modification logs to retrieve indications of recently written pages.

10. The apparatus of claim 7 , the graphics controller comprising a second processor component to execute at least one of the retrieval component or the scan component.

11. The apparatus of claim 10 , the second processor component to selectively execute at least one of the retrieval component or the scan component based on a current degree of use of processing resources of the second processor component by graphics operations performed by the second processor component.

12. The apparatus of claim 7 , comprising a network interface to couple the processing device to a network, the scan component to operate the network interface to disconnect the processing device from the network in response to detection of malware within a page.

13. A computer-implemented method for supporting secure processing comprising:

generating, by a first processor component of a processing device, entries in a chronological order within a first page modification log maintained within a first storage divided into multiple pages, each entry to indicate a write access made by the first processor component to a page of the multiple pages;

recurringly retrieving, by a graphics controller of the processing device, indications from the first page modification log of at least one recently written page of the multiple pages; and

recurringly scanning, by the graphics controller, the at least one recently written page to detect malware within the at least one recently written page.

14. The computer-implemented method of claim 13 , comprising:

providing address translations for accesses to pages of the multiple pages to support virtual addressing based on the multiple pages; and

generating each entry within the first page modification log in response to providing an address translation for a write access to a page of the multiple pages.

15. The computer-implemented method of claim 14 , comprising:

generating, by the first processor component, multiple layers of page tables within the first storage; and

walking, by the first processor component, the multiple layers of page tables to translate addresses to support multiple virtual machines (VMs) generated by a host OS and to enable a guest OS that employs virtual addressing within one of the VMs to access at least a subset of the multiple pages associated with the one of the VMs by the host OS.

16. The computer-implemented method of claim 15 , comprising:

generating, by the first processor component, the entries within multiple page modification logs, each VM associated with at least one page modification log of the multiple page modification logs, the multiple page modification logs comprising the first page modification log; and

recurringly retrieving, by the graphics controller, indications from the multiple page modification logs of recently written pages.

17. The computer-implemented method of claim 13 , comprising:

analyzing an address of a page in which the malware is detected to determine a severity associated with the malware; and

providing an indication of the malware detected within the page to a security routine executed by the first processor component or transmitting an indication of the malware detected within the page to a security server via a network based on the severity.

18. The computer-implemented method of claim 13 , comprising operating, by the graphics controller, a network interface of the processing device to disconnect the processing device from a network in response to detecting malware within a page.

19. At least one non-transitory machine-readable storage medium comprising instructions that when executed by a processing device, cause the processing device to:

generate, by a first processor component of a processing device, entries in a chronological order within a first page modification log maintained within a first storage divided into multiple pages, each entry to indicate a write access made by the first processor component to a page of the multiple pages;

recurringly retrieve, by a graphics controller of the processing device, indications from the first page modification log of at least one recently written page of the multiple pages; and

recurringly scan, by the graphics controller, the at least one recently written page to detect malware within the at least one recently written page.

20. The at least one non-transitory machine-readable storage medium of claim 19 , the processing device caused to:

provide address translations for accesses to pages of the multiple pages to support virtual addressing based on the multiple pages; and

generate each entry within the first page modification log in response to providing an address translation for a write access to a page of the multiple pages.

21. The at least one non-transitory machine-readable storage medium of claim 20 , the processing device caused to:

generate, by the first processor component, multiple layers of page tables within the first storage; and

walk, by the first processor component, the multiple layers of page tables to translate addresses to support multiple virtual machines (VMs) generated by a host OS and to enable a guest OS that employs virtual addressing within one of the VMs to access at least a subset of the multiple pages associated with the one of the VMs by the host OS.

22. The at least one non-transitory machine-readable storage medium of claim 20 , the first page modification log to accommodate a limited quantity of the entries, the processing device caused to generate, by the first processor component, the entries within a second page modification log maintained within the first storage to allow more time for retrieving indications of recently written pages from the entries within the first page modification log before the entries within the first page modification log are overwritten with new entries generated by the address translator.

23. The at least one non-transitory machine-readable storage medium of claim 22 , the processing device caused to:

rotate, by the first processor component, among at least the first and second page modification logs to generate the entries; and

rotate, by the graphics controller, among at least the first and second page modification logs to retrieve indications of recently written pages.

24. The at least one non-transitory machine-readable storage medium of claim 19 , the graphics controller comprising a second processor component, the processing device caused to selectively perform at least one of the recurring retrieval of indications from the first page modification log of at least one recently written page of the multiple pages, or the recurring scan of the at least one recently written page to detect malware within the at least one recently written page based on a current degree of use of processing resources of the second processor component by graphics operations performed by the second processor component.

25. The at least one non-transitory machine-readable storage medium of claim 24 , the graphics operations comprising at least one of providing a user interface, rendering a three-dimensional object or decompressing a motion video.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2016
From: LEMAY, MICHAEL; DURHAM, DAVID M.
To: INTEL CORPORATION
Reel/Frame 040069/0981 →
Continuity (1)
Related Publication 20170185773A1 · Jun 29, 2017