首页> 外国专利> Method and apparatus for enforcing a mandatory security policy on an operating system (OS) independent anti-virus (AV) scanner

Method and apparatus for enforcing a mandatory security policy on an operating system (OS) independent anti-virus (AV) scanner

机译:用于在独立于操作系统(OS)的防病毒(AV)扫描程序上实施强制性安全策略的方法和装置

摘要

An antivirus (AV) application specifies a fault handler code image, a fault handler manifest, a memory location of the AV application, and an AV application manifest. A loader verifies the fault handler code image and the fault handler manifest, creates a first security domain having a first security level, copies the fault handler code image to memory associated with the first security domain, and initiates execution of the fault handler. The loader requests the locking of memory pages in the guest OS that are reserved for the AV application. The fault handler locks the executable code image of the AV application loaded into guest OS memory by setting traps on selected code segments in guest OS memory.
机译:防病毒(AV)应用程序指定故障处理程序代码映像,故障处理程序清单,AV应用程序的内存位置和AV应用程序清单。加载程序验证故障处理程序代码映像和故障处理程序清单,创建具有第一安全级别的第一安全域,将故障处理程序代码映像复制到与第一安全域关联的内存,并启动故障处理程序的执行。加载程序请求锁定来宾OS中为AV应用程序保留的内存页面。故障处理程序通过在来宾OS存储器中选定代码段上设置陷阱来锁定加载到来宾OS存储器中的AV应用程序的可执行代码映像。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号