首页> 外国专利> A METHOD FOR ROOTKIT RESISTANCE BASED ON A TRUSTED CHIP

A METHOD FOR ROOTKIT RESISTANCE BASED ON A TRUSTED CHIP

机译:一种基于信任芯片的rootkit抗性方法

摘要

THE METHOD AND SYSTEM ARE DISCLOSED FOR DISK PROTECTION AGAINST PERSISTENT ROOTKITS. THE METHOD INCLUDES DISK PROTECTION AGAINST PERSISTENT ROOTKITS (ROOTKITS THAT ATTEMPT TO MODIFY THE SYSTEM IMAGE) BASED ON TRUSTED CHIP (34). FURTHER, THE METHOD PROVIDES A REAL-TIME PROTECTION TO PREVENT ROOTKIT FROM BEING WRITTEN TO SYSTEM IMAGE. THE PRESENT METHOD IS FOR DISK PROTECTION AGAINST PERSISTENT ROOTKITS (ROOTKITS THAT ATTEMPT TO MODIFY THE SYSTEM IMAGE) BASED ON THE TRUSTED CHIP (34). THE METHOD LABELS ALL BLOCKS IN THE DISK WHERE THE SYSTEM FILES ARE LABELED AS SYSTEM AREA BLOCKS AND THE REMAINING BLOCKS AS USER AREA BLOCKS. THE LABELED BLOCKS ARE STORED IN A TABLE PROTECTED BY THE TRUSTED CHIP INTEGRATED ON THE HOST MACHINE. DURING THE NORMAL PROCESS, ALL WRITE OPERATIONS TO SYSTEM AREA ARE VERIFIED BEFORE WRITING IS MADE TO THE SYSTEM AREA BLOCKS. THE MOST ILLUSTRATIVE DRAWING: FIGURE 3
机译:公开了针对永久性根盘的磁盘保护的方法和系统。该方法包括基于可信任芯片(34)的针对永久性根目录(尝试修改系统图像的根目录)的磁盘保护。此外,该方法提供了实时保护,以防止rootkit被写入系统图像。当前的方法是基于受信任的芯片(34)针对永久根目录(尝试修改系统图像的根目录)进行磁盘保护。该方法将磁盘中的所有块标记为系统文件,其中系统文件标记为系统区域块,其余的块标记为用户区域块。标签块存储在一个表中,该表由主机上集成的受信任芯片保护。在正常过程中,在对系统区域块进行写入之前,已验证对系统区域的所有写操作。最具说明性的图纸:图3

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号