首页> 外国专利> SYSTEMS AND METHODS FOR PROVIDING A COMPUTING DEVICE HAVING A SECURE OPERATING SYSTEM KERNEL

SYSTEMS AND METHODS FOR PROVIDING A COMPUTING DEVICE HAVING A SECURE OPERATING SYSTEM KERNEL

机译:提供具有安全操作系统内核的计算设备的系统和方法

摘要

A method and apparatus for resisting malicious code in a computing device. A software component corresponding to an operating system kernel is analyzed prior to executing the software component to detect the presence of one or more specific instructions such as malicious code, a change in mode permissions or instructions to modify or turn off security monitoring software, and taking a graduated action in response to the detection of one or more specific instructions. The graduated action taken is specified by a security policy (or policies) stored on the computing device. The analyzing may include off-line scanning of a particular code or portion of code for certain instructions, or codes, or patterns, and includes scanning in real-time as the kernel or kernel module is loading while the code being scanned is not yet executing (i.e., it is not yet "on-line"). Analysis of other code proceeds according to policies.
机译:一种用于抵抗计算设备中的恶意代码的方法和装置。在执行软件组件之前,先对与操作系统内核相对应的软件组件进行分析,以检测是否存在一个或多个特定指令,例如恶意代码,模式许可权的更改或修改或关闭安全监控软件的指令,并采取措施。响应于检测到一个或多个特定指令而采取的分级操作。所采取的分级动作由存储在计算设备上的一个或多个安全策略指定。该分析可以包括对某些指令,代码或模式的特定代码或部分代码进行离线扫描,并且包括当内核或内核模块正在加载而未扫描的代码尚未执行时实时扫描。 (即,尚未“在线”)。其他代码将根据政策进行分析。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号