IP Library Granted Patent US 9,639,698
Granted Patent B2
US 9,639,698 · App. 14/942,184 · Granted May 2, 2017

Systems and methods for active operating system kernel protection

Inventors: Maxim V. Yudin (St. Petersburg, RU); Alexander S. Tarasenko (St. Petersburg, RU); Vyacheslav I. Levchenko (St. Petersburg, RU); Igor Y. Kumagin (Nizhny Novgorod, RU)
Assignee: AO KASPERSKY LAB
G06F21/562G06F9/45558G06F21/53G06F21/566G06F2009/45587G06F2009/45591G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,639,698
App. No.
14/942,184
Granted
May 2, 2017
Kind
B2
Abstract

Systems and methods for intercepting computing device system calls for a computing device including a kernel having a system call table. A hypervisor is executed on the computing device, the hypervisor configured to control at least one of the computing device processor registers. At least one modified kernel structure is created, the modified kernel structure including a modified system call table. A memory address of an original system call handler is determined, the original system call handler configured to receive kernel operation commands. A size of a loaded image of the original system call handler is determined. A copy of the original system call handler as a second system call handler is created, and the second system call handler intercepts a computing device system call.

Claims (11)

1. A computing device kernel comprising:

an address space;

an original system call handler loaded on the address space and configured to receive and execute computing device kernel operation commands; and

a substitute system call handler loaded on the address space, wherein the substitute system call handler is generated as a copy of the original system call handler by determining a memory address of the original system call handler and determining a size of a loaded image of the original system call handler,

wherein the substitute system call handler is configured to intercept a computing device system call as directed by a hypervisor operably coupled to the address space.

2. The computing device kernel of claim 1 , further comprising a modified system call table loaded on the address space, the modified system call table being a copy of an original system call table used by the original system call handler, the modified system call table configured for use with the substitute system call handler.

3. The computing device kernel of claim 2 , wherein the original system call table comprises a System Service Dispatch Table (SSDT).

4. The computing device kernel of claim 1 , further comprising one or more exception tables loaded on the address space, the one or more exception tables related to execution code of the substitute system call handler.

5. The computing device kernel of claim 1 , wherein the hypervisor is configured to control at least one computing device processor register through the substitute system call handler.

6. The computing device kernel of claim 5 , wherein the at least one computing device processor register comprises a Machine Specific Register (MSR).

7. The computing device kernel of claim 6 , wherein the substitute system call handler is configured to interface with a Kernel Patch Protection (KPP) engine without detection of the substitute system call handler.

Assignments (2)
CHANGE OF NAME Recorded Apr 14, 2016
From: KASPERSKY LAB ZAO
To: AO KASPERSKY LAB
Reel/Frame 038430/0261 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2015
From: YUDIN, MAXIM V.; TARASENKO, ALEXANDER S.; LEVCHENKO, VYACHESLAV I.; KUMAGIN, IGOR Y.
To: KASPERSKY LAB ZAO
Reel/Frame 037050/0283 →
Continuity (2)
Continuation 14601331 · Jan 21, 2015
Related Publication 20160210456A1 · Jul 21, 2016