EP2691908A2

System and method for virtual machine monitor based anti-malware security

Abstract

This record has no abstract on file.

Term

5.5 yearsto projected expiry

Projected expiry 27 March 2032, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

142 claims: 15 independent, 127 dependent

  1. 1
    Claims of equivalent WO 2012135192 A2 WHAT IS CLAIMED IS:1. A system for securing an electronic device, comprising: a memory;a processor;one or more operating systems residing in the memory for execution by the processor;a resource of the electronic device communicatively coupled to the operating system;a virtual machine monitor configured to execute on the electronic device at a level below all of the operating systems of the electronic device accessing the resource;and a security agent configured to execute on the electronic device at a level below all operating systems of the electronic device accessing the resource;wherein the virtual machine monitor is configured to: intercept a request of the resource made from a level above the virtual machine monitor;and inform the security agent of the request;and wherein the security agent is configured to determine whether the request is indicative of malware.
  2. 2
    The system of Claim 1, wherein if the request is indicative of malware, the security agent is configured to deny the request.
  3. 3
    The system of Claim 1, further comprising a server coupled to the security agent, the server configured to provide security rules to the security agent, the security rules used to determine whether the request is indicative of malware.
  4. 4
    The system of Claim 3, wherein the server is configured to:receive information about a behavior on the electronic device observed by the virtual machine monitor and comprising the request;and determine whether the observed behavior indicates malware.
  5. 5
    The system of Claim 1, wherein the virtual machine monitor and the security agent are implemented by the same software module.
  6. 6
    The system of Claim 1, wherein the virtual machine monitor and the security agent operate within a bare metal layer of the electronic device.
  7. 7
    The system of Claim 1, wherein the processor comprises a virtualization extension for the resource.
  8. 8
    The system of Claim 7, wherein the virtual machine monitor uses the virtualization extension to intercept the request of the resource.
  9. 9
    The system of Claim 1, wherein the resource comprises a register of the processor.
  10. 10
    The system of Claim 1, wherein the resource comprises physical memory.
  11. 11
    The system of Claim 1, wherein the resource comprises virtualized memory.
  12. 12
    The system of Claim 11, wherein the security agent is configured to determine from one or more security rules whether attempted access of one or more pages of virtualized memory is indicative of malware.
  13. 13
    The system of Claim 1, further comprising an operating system security agent running in one or more of the operating systems and communicatively coupled to the security agent, wherein the security agent is configured to provide security information regarding one or more elements in the one or more operating systems that made the request of the resource.
  14. 14
    The system of Claim 13, wherein the security agent is configured to validate the operating system security agent.
  15. 15
    The system of Claim 1, wherein the security agent is configured to:scan the memory;and determine whether any contents of the memory are known to be malicious or safe.
  16. 16
    A system for securing an electronic device, comprising:a memory;a processor;one or more operating systems residing in the memory for execution by the processor;a resource of the electronic device communicatively coupled to the operating system;a virtual machine monitor configured to execute on the electronic device at a higher priority than all of the operating systems of the electronic device accessing the resource, such priority defined by the processor;and a security agent configured to execute on the electronic device at a higher priority than all of the operating systems of the electronic device accessing the resource, such priority defined by the processor;wherein the virtual machine monitor is configured to: intercept a request of the resource made from an entity with less priority than the virtual machine monitor;and inform the security agent of the request;and wherein the security agent is configured to determine whether the request is indicative of malware.
  17. 17
    A system for securing an electronic device, comprising:a memory;a processor;one or more operating systems residing in the memory for execution by the processor;a resource of the electronic device coupled to the operating system;a virtual machine monitor configured to execute on the electronic device on a more privileged ring of execution than all of the operating systems of the electronic device accessing the resource;and a security agent configured to execute on the electronic device on a more privileged ring of execution than all operating systems of the electronic device;wherein the virtual machine monitor is configured to: intercept a request of the resource, the request made from a less privileged ring of execution than the virtual machine monitor;and inform the security agent of the request;and wherein the security agent is configured to determine whether the request is indicative of malware.
  18. 18
    The system of Claim 17, wherein the virtual machine monitor executes in a ring of execution of the system corresponding to ring -1.
  19. 19
    A method for securing an electronic device, comprising at a level below all of the operating systems of the electronic device accessing a resource:intercepting a request of the resource of the electronic device made from a higher level, the resource communicatively coupled to the operating system;and determining whether the request is indicative of malware.
  20. 32
    A method for securing an electronic device, comprising at a higher priority than all of the operating systems of the electronic device accessing a resource, such priority defined by a processor of the electronic device:intercepting a request of the resource made from an entity with less priority;and determining whether the request is indicative of malware.
  21. 33
    A method for securing an electronic device, comprising on a more privileged ring of execution than all of the operating systems of the electronic device accessing a resource:intercepting a request of the resource, the request made from a less privileged ring of execution;and determining whether the request is indicative of malware.
  22. 34
    The method of Claim 33, wherein the more privileged ring of execution corresponds to ring -1.
  23. 35
    An article of manufacture comprising:a computer readable medium;and computer-executable instructions carried on the computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to, at a level below all of the operating system of an electronic device accessing a resource: intercept a request of the resource of the electronic device made from a higher level, the resource communicatively coupled to the operating system;and determine whether the request is indicative of malware.
  24. 36
    The article of Claim 35, wherein the processor is further caused to:if the request is indicative of malware, deny the request.
  25. 37
    The article of Claim 35, wherein the processor is further caused to receive security rules from a server, the security rules used to determine whether the request is indicative of malware.
  26. 38
    The article of Claim 37, wherein the processor is further caused to:send information about a behavior observed on the electronic device;and receive a determination whether the behavior indicates malware.
  27. 39
    The article of Claim 35, wherein the processor is caused to intercept the request and determine whether the request is indicative of malware is within a bare metal layer of the electronic device.
  28. 40
    The article of Claim 35, further comprising causing the processor to use a virtualization extension to intercept the request of the resource, the virtualization extension included in a processor of the electronic device and associated with the resource.
  29. 41
    The article of Claim 35, wherein the resource comprises a register of the processor.
  30. 42
    The article of Claim 35, wherein the resource comprises physical memory.
  31. 43
    The article of Claim 35, wherein the resource comprises virtualized memory.
  32. 44
    The article of Claim 43, wherein the processor is further caused to determine from one or more security rules whether attempted access of one or more pages of virtualized memory is indicative of malware.
  33. 45
    The article of Claim 35, wherein the processor is further caused to receive information regarding one or more elements in an operating system of the electronic device, the elements making the request of the resource.
  34. 46
    The article of Claim 35, wherein the processor is further caused to validate the security of an operating system security agent, the operating security agent configured to gather the information regarding one or more elements in an operating system of the electronic device.
  35. 47
    The article of Claim 35, wherein the processor is further caused to:scan a memory of the electronic device;and determine whether any contents of the memory are known to be malicious
  36. 48
    An article of manufacture comprising:a computer readable medium;and computer-executable instructions carried on the computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to, at a higher priority than all of the operating systems of the electronic device accessing the resource, the priority defined the processor: intercept a request of the resource made from an entity with less priority;and determine whether the request is indicative of malware.
  37. 49
    An article of manufacture comprising a computer readable medium; and computer-executable instructions carried on the computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to, on a more privileged ring of execution than all of the operating systems of the electronic device accessing a resource:intercept a request of the resource, the request made from a less privileged ring of execution;and determine whether the request is indicative of malware.
  38. 50
    A system for securing an electronic device, comprising:a non- volatile memory;a processor coupled to the non-volatile memory;a resource of the electronic device;firmware residing in the non-volatile memory and executed by the processor, the firmware communicatively coupled to the resource of an electronic device;and a firmware security agent residing in the firmware, the firmware security agent configured to, at a level below all of the operating systems of the electronic device accessing the resource: intercept a request for the resource;and determine whether the request is indicative of malware.
  39. 51
    The system of Claim 50, wherein the firmware resides in a controller of a peripheral of the electronic device.
  40. 52
    The system of Claim 50, wherein the resource comprises an input/output component of the electronic device.
  41. 53
    The system of Claim 50, wherein the resource comprises a keyboard.
  42. 54
    The system of Claim 50, wherein the resource comprises a display device.
  43. 55
    The system of Claim 50, wherein the resource comprises a disk.
  44. 56
    The system of Claim 50, wherein the request comprises an input or output command.
  45. 57
    The system of Claim 56, wherein determining whether the request is indicative of malware comprises evaluating whether the value of the input or output command is indicative of malware.
  46. 58
    The system of Claim 50, further comprising:an input and/or output (I/O) device comprising the memory and processor, the I/O device communicatively coupled to an operating system of the electronic device;a security agent communicatively coupled to the firmware security agent, wherein: configuring the firmware security agent to determine whether the request indicates malware comprises configuring the firmware security agent to send information to the security agent, the information comprising the request;and the security agent is configured to access one or more security rules to determine whether the information indicates malware.
  47. 59
    The system of Claim 58, wherein the security agent operates within a bare metal layer of the electronic device.
  48. 60
    The system of Claim 58, further comprising an operating system security agent running in the operating system and communicatively coupled to the security agent, wherein the security agent is configured to provide information to security agent, the information regarding one or more elements in the operating system that made the request of the resource.
  49. 61
    The system of Claim 58, wherein the firmware security agent is configured to validate the security agent.
  50. 62
    The system of Claim 58, wherein the security agent is configured to:execute at a level below all operating systems of the electronic device accessing the resource;and receive the request from a level above the security agent.
  51. 63
    The system of Claim 58, wherein the security agent is configured to:execute at a higher priority than all operating systems of the electronic device accessing the resource, such priority defined by the processor;and receive the request is from an entity with less priority than the security agent.
  52. 64
    The system of Claim 58, wherein the security agent is configured to:execute on a more privileged ring of execution than all operating systems of the electronic device accessing the resource;and receive the request from a less privileged ring of execution than the security agent.
  53. 65
    A method for securing an electronic device, comprising:in firmware communicatively coupled to a resource, the resource coupled to the electronic device and the firmware residing in a non-volatile memory, intercepting a request for the resource at a level below all of the operating systems of the electronic device accessing the resource;consulting one or more security rules;and based on the one or more security rules, determining whether the request is indicative of malware.
  54. 66
    The method of Claim 65, wherein determining whether the request is indicative of malware comprises:sending information about the request to a protection server;and receiving a determination about the request from the protection server.
  55. 67
    The method of Claim 65, wherein the request is intercepted in firmware resident in a controller of a peripheral of the electronic device.
  56. 68
    The method of Claim 65, wherein the resource comprises an input/output component of the electronic device. The method of Claim 65, wherein the resource comprises an keyboard.
  57. 69
    70. The method of Claim 65, wherein the resource comprises a display device.
  58. 70
    71. The method of Claim 65, wherein the resource comprises a disk.
  59. 71
    72. The method of Claim 65, wherein the request comprises an input or output command.
  60. 72
    73. The method of Claim 65, further comprising communicating with a security agent to receive one or more security rules.
  61. 73
    74. The method of Claim 73, further comprising :intercepting the request in the firmware of an input and/or output (I/O) device;wherein determining whether the request whether the request indicates malware comprises: sending information to the security agent, the information comprising the request;and accessing one or more security rules from the security agent to determine whether the request indicates malware.
  62. 74
    75. The method of Claim 73, wherein accessing one or more security rules from the security agent is accomplished within a bare metal layer of the electronic device.
  63. 75
    76. The method of Claim 73, further comprising:communicating with an operating system security agent running in an operating system of the electronic device;and receiving information regarding one or more elements in the operating system that made the request of the resource.
  64. 76
    77. The method of Claim 73, further comprising validating the security agent.
  65. 77
    78. The method of Claim 73 :wherein the security agent is executing at a level below all operating methods of the electronic device;and further comprising receiving the request from a level above the security agent.
  66. 78
    79. The method of Claim 73 :wherein the security agent is executing at a higher priority than all operating systems of the electronic device accessing the resource, such priority defined by the processor;and further comprising receiving the request from an entity with less priority than the security agent.
  67. 79
    80. The method of Claim 73 :wherein the security agent is executing on a more privileged ring of execution than all operating systems of the electronic device accessing the resource;and further comprising receiving the request from a less privileged ring of execution than the security agent.
  68. 80
    81. An article of manufacture comprising:a computer readable medium;and computer-executable instructions carried on the computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to: in firmware communicatively coupled to a resource, the resource coupled to the electronic device and the firmware residing in a non-volatile memory, intercept a request for the resource at a level below all of the operating systems of the electronic device accessing the resource;consult one or more security rules;and based on the one or more security rules, determine whether the request is indicative of malware.
  69. 81
    82. The article of Claim 81, wherein the processor is caused to intercept the request in firmware residing in a controller of a peripheral of the electronic device.
  70. 82
    83. The article of Claim 81, wherein the resource comprises an input/output component of the electronic device.
  71. 83
    84. The article of Claim 81 , wherein the resource comprises a keyboard.
  72. 84
    85. The article of Claim 81, wherein the resource comprises a display device.
  73. 85
    86. The article of Claim 81 , wherein the resource comprises a disk.
  74. 86
    87. The article of Claim 81, wherein the request comprises an input or output command.
  75. 87
    88. The article of Claim 81, further comprising causing the processor to communicate with a security agent to receive one or more security rules.
  76. 88
    89. The article of Claim 88, further comprising causing the processor to:intercept the request in the firmware of an input and/or output (I/O) device;wherein determining whether the request whether the request indicates malware comprises causing the processor to: send information to the security agent, the information comprising the request;and access one or more security rules from the security agent to determine whether the request indicates malware.
  77. 89
    90. The article of Claim 88, wherein accessing one or more security rules from the security agent comprises is accomplished within a bare metal layer of the electronic device.
  78. 90
    91. The article of Claim 88, wherein the processor is further caused to:communicate with an operating system security agent running in an operating system of the electronic device;and receive information regarding one or more elements in the operating system that made the request of the resource.
  79. 91
    92. The article of Claim 88, wherein the processor is further caused to validate the security agent.
  80. 92
    93. The article of Claim 88, wherein:the security agent is configured to execute at a level below all operating articles of the electronic device;and the processor is further caused to receive the request from a level above the security agent.
  81. 93
    94. The article of Claim 88, wherein:the security agent is configured to execute at a higher priority than all operating systems of the electronic device accessing the resource, such priority defined by the processor;and the processor is further caused to receive the request from an entity with less priority than the security agent.
  82. 94
    95. The article of Claim 88, wherein:the security agent is configured to execute on a more privileged ring of execution than all operating systems of the electronic device accessing the resource;and the processor is further caused to receive the request the request from a less privileged ring of execution than the security agent.
  83. 95
    96. A system for securing an electronic device, comprising:a processor comprising microcode;a resource coupled to the processor;a microcode security agent embodied the microcode, the microcode security agent configured to: intercept a communication, the communication comprising a request made of the resource or information generated from the resource;and determine whether the communication is indicative of malware.
  84. 96
    97. The system of Claim 96, wherein the resource comprises physical memory. The system of Claim 96, wherein the resource comprises a processor 99. The system of Claim 96, wherein the resource comprises a processor exception.
  85. 97
    100. The system of Claim 96, wherein the resource comprises a register.
  86. 98
    101. The system of Claim 96, wherein the resource comprises a processor interrupt.
  87. 99
    102. The system of Claim 96, wherein:the communication comprises a processor instruction;and determining whether the communication is indicative of malware comprises evaluating whether the processor instruction is indicative of malware.
  88. 100
    103. The system of Claim 102, wherein determining whether the communication is indicative of malware comprises evaluating whether a source address of the processor instruction is indicative of malware.
  89. 101
    104. The system of Claim 102, wherein determining whether the communication is indicative of malware comprises evaluating whether a target address of the processor instruction is indicative of malware.
  90. 102
    105. The system of Claim 102, wherein determining whether the communication is indicative of malware comprises evaluating whether an operand of the processor instruction is indicative of malware.
  91. 103
    106. The system of Claim 96, further comprising:a below-operating-system security agent communicatively coupled to the microcode security agent, wherein: configuring the microcode security agent to determine whether the communication indicates malware comprises: configuring the microcode security agent to send information to the security agent, the information comprising the communication;and the below-operating-system security agent is configured to access one or more security rules to determine whether the information indicates malware.
  92. 104
    107. The system of Claim 106, wherein the below-operating-system security agent is configured to operate within a bare metal layer of the electronic device.
  93. 105
    108. The system of Claim 106, further comprising an operating system security agent running in an operating system of the system and communicatively coupled to the below-operating-system security agent, wherein the operating system security agent is configured to provide the security agent with information regarding one or more elements in the operating system associated with the communication.
  94. 106
    109. The system of Claim 106, wherein the microcode security agent is configured to validate the security of the below-operating-system security agent.
  95. 107
    110. The system of Claim 106, wherein:the below-operating-system security agent is configured to execute at a level below all operating systems of the electronic device accessing the resource;and the communication has a source or destination of a level above the below- operating-system security agent.
  96. 108
    111. The system of Claim 106, wherein:the below-operating-system security agent executes at a higher priority than all operating systems of the electronic device accessing the resource, such priority defined by the processor;and the communication has a source or destination of an entity with less priority than the below-operating-system security agent.
  97. 109
    112. The system of Claim 106, wherein:the below-operating-system security agent executes on a more privileged ring of execution than all operating systems of the electronic device accessing the resource;and the communication has a source or destination of a less privileged ring of execution than the below-operating-system security agent.
  98. 110
    113. A method for securing an electronic device, comprising:using a microcode security agent embodied in microcode of a processor, intercepting a communication comprising a request made of a resource or information generated from the resource, the resource coupled to the processor;consulting one or more security rules;and based on the one or more security rules, determining whether the communication is indicative of malware.
  99. 111
    114. The method of Claim 113, wherein the resource comprises physical memory.
  100. 112
    115. The method of Claim 113, wherein the resource comprises a processor flag.
  101. 113
    116. The method of Claim 113, wherein the resource comprises a processor exception.
  102. 114
    117. The method of Claim 113, wherein the resource comprises a register.
  103. 115
    118. The method of Claim 113, wherein the resource comprises a processor interrupt.
  104. 116
    119. The method of Claim 113, wherein:the communication comprises a processor instruction;and determining whether the communication is indicative of malware comprises evaluating whether the processor instruction is indicative of malware.
  105. 117
    120. The method of Claim 119, wherein determining whether the communication is indicative of malware comprises evaluating whether a source address of the processor instruction is indicative of malware.
  106. 118
    121. The method of Claim 119, wherein determining whether the communication is indicative of malware comprises evaluating whether a target address of the processor instruction is indicative of malware.
  107. 119
    122. The method of Claim 119, wherein determining whether the communication is indicative of malware comprises evaluating whether an operand of the processor instruction is indicative of malware.
  108. 120
    123. The method of Claim 119, wherein determining whether the communication indicates malware comprises sending information to a below- operating-system security agent, the information comprising the communication, the security agent configured to access one or more security rules to determine whether the information indicates malware.
  109. 121
    124. The method of Claim 123, wherein the longhorn security agent is configured to operate within a bare metal layer of the electronic device.
  110. 122
    125. The method of Claim 123, further comprising:communicating with an operating system security agent running in an operating system of the electronic device;and receiving information regarding one or more elements in the operating system associated with the communication with the resource.
  111. 123
    126. The method of Claim 123, further comprising validating the instance of the below-operating-system security agent.
  112. 124
    127. The method of Claim 123, wherein:the below-operating-system security agent is configured to execute at a level below all operating methods of the electronic device;and the request is made from a level above the below-operating-system security agent.
  113. 125
    128. The method of Claim 123, wherein:the below-operating-system security agent is configured to execute at a higher priority than all operating systems of the electronic device accessing the resource, such priority defined by the processor;and the request is made from an entity with less priority than the below-operating- system security agent.
  114. 126
    129. The method of Claim 123, wherein:the below-operating-system security agent is configured to execute on a more privileged ring of execution than all operating systems of the electronic device accessing the resource;and the request is made from a less privileged ring of execution than the below- operating-system security agent.
  115. 127
    130. An article of manufacture comprising:a computer readable medium;and computer-executable microcode embodied in instructions carried on the computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to: using the microcode instructions, intercept a communication, the communication comprising a request made of a resource or information generated from the resource, the resource coupled to the processor;consult one or more security rules;and based on the one or more security rules, determine whether the communication is indicative of malware.
  116. 128
    131. The article of Claim 130, wherein the resource comprises physical memory.
  117. 129
    132. The article of Claim 130, wherein the resource comprises a processor flag.
  118. 130
    133. The article of Claim 130, wherein the resource comprises physical memory.
  119. 131
    134. The article of Claim 130, wherein the resource comprises a processor exception.
  120. 132
    135. The article of Claim 130, wherein the resource comprises a register.
  121. 133
    136. The article of Claim 130, wherein the resource comprises a processor interrupt.
  122. 134
    137. The article of Claim 130, wherein:the communication comprises a processor instruction;and determining whether the communication is indicative of malware comprises causing the processor to evaluate whether the processor instruction is indicative of malware.
  123. 135
    138. The article of Claim 130, wherein determining whether the communication is indicative of malware comprises causing the processor to evaluate whether a source address of the processor instruction is indicative of malware.
  124. 136
    139. The article of Claim 130, wherein determining whether the communication is indicative of malware comprises causing the processor to evaluate whether a target address of the processor instruction is indicative of malware.
  125. 137
    140. The article of Claim 130, wherein determining whether the communication is indicative of malware comprises causing the processor to evaluate whether an operand of the processor instruction is indicative of malware.
  126. 138
    141. The article of Claim 130, wherein determining whether the communication is indicative of malware comprises causing the processor to send information to a below-operating-system security agent, the information comprising the communication, the below-operating-system security agent configured to access one or more security rules to determine whether the information indicates malware.
  127. 139
    142. The article of Claim 141, further comprising causing the processor to validate the instance of the below-operating-system security agent.
  128. 140
    143. The article of Claim 141, wherein:the below-operating-system security agent is configured to execute at a level below all operating methods of the electronic device;and the request is made from a level above the below-operating-system security agent.
  129. 141
    144. The article of Claim 141, wherein:the below-operating-system security agent is configured to execute at a higher priority than all operating systems of the electronic device accessing the resource, such priority defined by the processor;and the request is made from an entity with less priority than the below-operating- system security agent.
  130. 142
    145. The article of Claim 141, wherein:the below-operating-system security agent is configured to execute on a more privileged ring of execution than all operating systems of the electronic device accessing the resource;and the request is made from a less privileged ring of execution than the below- operating-system security agent.
Independent claims130