IP Library › Granted Patent US 12,204,639
Granted Patent B2
US 12,204,639 · App. 16/523,085 · Granted Jan 21, 2025

Monitoring operating system invariant information

Inventors: Geoffrey Ndu (Bristol, GB); Nigel Edwards (Bristol, GB)
Assignee: Hewlett Packard Enterprise Development LP
G06F21/54G06F9/45558G06F11/3037G06F21/126G06F21/562G06F21/566G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,204,639
App. No.
16/523,085
Granted
Jan 21, 2025
Kind
B2
Abstract

In some examples, a system executes a monitor separate from an operating system (OS) that uses mapping information in accessing data in a physical memory. The monitor identifies, using the mapping information, invariant information, that comprises program code, of the OS without suspending execution of the OS, the identifying comprising the monitor accessing the physical memory independently of the OS. The monitor determines, based on monitoring the invariant information of the OS, whether a security issue is present.

Claims (43)

1. A non-transitory machine-readable storage medium comprising instructions that upon execution cause a system to:

execute a monitor separate from an operating system (OS) that uses mapping information in accessing data in a physical memory, wherein the mapping information maps virtual addresses to physical addresses of the physical memory;

receive, by the monitor from an agent, metadata indicating a storage location of the mapping information;

access, by the monitor without suspending execution of the OS, the mapping information using a virtual address in the metadata, the virtual address related to invariant information comprising program code of the OS;

receive, by the monitor, a physical address translated by the mapping information from the virtual address;

access, by the monitor, a memory location specified by the physical address to retrieve the invariant information of the OS from the physical memory independently of the OS; and

determine, by the monitor based on monitoring the invariant information of the OS, whether a security issue is present.

2. The non-transitory machine-readable storage medium of claim 1 , wherein the access of the memory location comprises the monitor accessing the physical memory directly over an interconnect independently of the OS.

3. The non-transitory machine-readable storage medium of claim 1 , wherein the metadata comprises a virtual memory map that indicates portions of a virtual address space that are assigned for respective uses by the OS, and wherein determining whether the security issue is present is further based on the virtual memory map.

4. The non-transitory machine-readable storage medium of claim 1 , wherein the metadata comprises a virtual address of critical information of the OS or of static information of the OS, wherein the invariant information monitored by the monitor comprises the critical information or the static information.

5. The non-transitory machine-readable storage medium of claim 1 , wherein the metadata comprises a page frame management data structure comprising information for page frames, wherein the invariant information monitored by the monitor comprises a page frame.

6. The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the system to:

detect new executable code; and

determine that an attack is occurring responsive to:

detecting that the new executable code is corrupted based on the metadata, or

detecting that the new executable code is within or outside of a specified virtual address region.

7. The non-transitory machine-readable storage medium of claim 1 , wherein determining whether the security issue is present comprises comparing a hash value of the invariant information at runtime of the OS to a baseline hash value of the invariant information.

8. The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the system to:

use a process descriptor to verify an integrity of an OS process.

9. The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the system to:

detect a hidden process by comparing entries of a first list that lists all processes with entries of a second list that lists scheduled processes.

10. A system comprising:

a physical memory;

a first processor;

a second processor;

an operating system (OS) executable on the first processor, the OS to use mapping information in accessing data in the physical memory, wherein the mapping information maps virtual addresses to physical addresses of the physical memory;

a monitor executable on the second processor that is different from the first processor to:

receive, from an agent, metadata indicating a storage location of the mapping information;

access, without suspending execution of the OS, the mapping information using a virtual address in the metadata, the virtual address related to invariant information comprising program code of the OS;

receive, at the monitor, a physical address translated by the mapping information from the virtual address;

access a memory location specified by the physical address to retrieve the invariant information of the OS from the physical memory independently of the OS; and

determine, based on monitoring the invariant information of the OS, whether a security issue is present.

11. The system of claim 10 , wherein the metadata comprises a virtual memory map that indicates portions of a virtual address space that are assigned for respective uses by the OS, and wherein determining whether the security issue is present is further based on the virtual memory map.

12. The non-transitory machine-readable storage medium of claim 1 , wherein executing the monitor separately from the OS comprises executing the monitor on a first processor and executing the OS on a second processor.

13. The non-transitory machine-readable storage medium of claim 1 , wherein the OS includes a hypervisor, and the determining comprises determining whether the security issue is present with the hypervisor, and wherein the monitor is a non-hypervisor-based monitor.

14. The non-transitory machine-readable storage medium of claim 1 , wherein the monitoring of the invariant information is performed without making a copy of the mapping information.

15. The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the system to:

detect an attack of the mapping information.

16. The non-transitory machine-readable storage medium of claim 15 , wherein the detecting of the attack of the mapping information is based on detecting that an entry of the mapping information has a privilege level different from a predetermined privilege level or that the entry of the mapping information has a mode different from a predetermined mode.

17. The non-transitory machine-readable storage medium of claim 1 , wherein the agent is part of the OS.

18. The system of claim 10 , wherein the monitor is executable on the second processor to:

detect an attack of the mapping information.

19. The system of claim 18 , wherein the detecting of the attack of the mapping information is based on detecting that an entry of the mapping information has a privilege level different from a predetermined privilege level or that the entry of the mapping information has a mode different from a predetermined mode.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 14, 2021
From: HEWLETT-PACKARD LIMITED
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 054993/0410 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2019
From: NDU, GEOFFREY; EDWARDS, NIGEL
To: HEWLETT-PACKARD LIMITED
Reel/Frame 049881/0069 →
Continuity (1)
Related Publication 20210026948A1 · Jan 28, 2021
References Cited (30)
US 9270697B2 · Ghosh et al. · 2016 [cited by applicant]
US 9702727B2 · Block · 2017 [cited by applicant]
US 20090217377A1 · Arbaugh et al. · 2009 [cited by applicant]
US 20100223447A1 · Serebrin · 2010 [cited by examiner]
US 20110022812A1 · van der Linden · 2011 [cited by examiner]
US 20110082962A1 · Horovitz · 2011 [cited by examiner]
US 20140157407A1 · Krishnan · 2014 [cited by examiner]
US 20140325644A1 · Oberg et al. · 2014 [cited by applicant]
US 20150271139A1 · Lukacs · 2015 [cited by examiner]
US 20160092678A1 · Probert · 2016 [cited by examiner]
US 20160203088A1 · Tsirkin · 2016 [cited by examiner]
US 20160291996A1 · Tsirkin · 2016 [cited by examiner]
US 20160378678A1 · Lemay · 2016 [cited by examiner]
US 20170149801A1 · Schilling · 2017 [cited by examiner]
US 20170249261A1 · Durham · 2017 [cited by examiner]
US 20170286694A1 · Swidowski · 2017 [cited by examiner]
Arm Limited, Architectures—Privilege and Exception Levels, Arm Developer downloaded Jul. 15, 2019 (10 pages). [cited by applicant]
Azab et al., Hypervision Across Worlds: Real-time Kernel Protection from the ARM TrustZone Secure World, CCS'14, Nov. 3-7, 2014 (13 pages). [cited by applicant]
Delgado, ResearchGate, Performance implications of System Management Mode, Conference Paper, Sep. 2013 (12 pages). [cited by applicant]
Guanglu Yan et al., “MOSKG: Countering Kernel Rootkits with a Secure Paging Mechanism,” May 26, 2015, pp. 1-23 (online). The Wiley Network, Retrieved from the Internet on May 21, 2019 at URL: <onlinelibrary.wiley.com/do… [cited by applicant]
Han et al., Myth and Truth about Hypervisor-Based Kernel Protector: The Reason Why You Need Shadow-Box, This paper was presented at Black Hat Asia 2017, Mar. 30-31, 2017, Singapore (13 pages). [cited by applicant]
Hojoon Lee et al., “A Dynamic Per-context Verification of Kernel Address Integrity from External Monitors,” Feb. 20, 2018, pp. 1-29, Computers & Security. [cited by applicant]
Lazaros Koromilas et al., “GRIM: Leveraging GPUs for Kernel Integrity Monitoring,” Sep. 1, 2016, pp. 1-21. [cited by applicant]
Petroni, Jr., et al., Copilot—a Coprocessor-based Kernel Runtime Integrity Monitor, 2004 (16 pages). [cited by applicant]
Ricklarabee.Blogspot, Never-Ending Security, Virtual Memory, Page Tables, and One Bit—CVE-2016-7255, Jan. 8, 2017 (22 pages). [cited by applicant]
Wikipedia, ARM architecture lasted edited Jul. 15, 2019 (37 pages). [cited by applicant]
Wikipedia, Hypervisor last edited Jun. 19, 2019 (7 pages). [cited by applicant]
Wikipedia, Page table last edited May 2, 2019 (4 pages). [cited by applicant]
Wikipedia, PCI Express last edited Jul. 12, 2019 (28 pages). [cited by applicant]
Wikipedia, System.map last edited on May 13, 2019 (3 pages). [cited by applicant]