EP2691908B1

System and method for virtual machine monitor based anti-malware security

Abstract

This record has no abstract on file.

EP2691908B1, drawing sheet 1
Sheet 1 of 64

Term

5.5 yearsleft in the term

Expires 27 March 2032.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

11 claims: 1 independent, 10 dependent

  1. 1
    A method for securing an electronic device (204) against malware, comprising:using a first security agent (216) embodied in microcode of a processor of an electronic device (204) to intercept a communication comprising a request made by an operating system (212) to a resource (214) of the electronic device (204) or information generated from the resource of the electronic device (204), the resource (214) coupled to the processor;consult one or more security rules;and based on the one or more security rules, determining whether the communication is indicative of malware, wherein the communication comprises a processor instruction, characterized in that determining whether the communication is indicative of malware comprises a second security agent (218) embedded in the operating system (212) to monitor for file writes performed by one or more drivers of the operating system (212), wherein the first security agent (216) monitors input and output commands of the operating system (212), and determines whether more write operations are performed than monitored by the second security agent (218);and wherein said one or more security rules are determined based on a number of times said one or more drivers are reported by the first security agent (216).
  2. 2
    The method of Claim 1, wherein the resource comprises physical memory, and determining whether the communication is indicative of malware is based upon whether the request of the physical memory is malicious.
  3. 3
    The method of Claim 1, wherein the resource comprises a processor flag, and determining whether the communication is indicative of malware is based upon whether the request of the processor flag is malicious.
  4. 4
    The method of Claim 1, wherein the resource comprises a processor exception, and determining whether the communication is indicative of malware is based upon whether the request of the processor exception is malicious.
  5. 5
    The method of Claim 1, wherein the resource comprises a register, and determining whether the communication is indicative of malware is based upon whether the request of the register is malicious.
  6. 6
    The method of Claim 1, wherein the resource comprises a processor interrupt, and determining whether the communication is indicative of malware is based upon whether the request of the processor interrupt is malicious.
  7. 7
    The method of Claim 1, wherein determining whether the communication is indicative of malware comprises evaluating whether a source address of the processor instruction is indicative of malware.
  8. 8
    The method of Claim 1, wherein determining whether the communication is indicative of malware comprises evaluating whether a target address of the processor instruction is indicative of malware.
  9. 9
    The method of Claim 1, wherein determining whether the communication is indicative of malware comprises evaluating whether an operand of the processor instruction is indicative of malware.
  10. 10
    An article of manufacture comprising:a computer readable medium;and computer-executable instructions carried on the computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to execute the method of any of claims 1-9.
  11. 11
    A system for securing an electronic device, comprising:a processor comprising microcode;a resource coupled to the processor;an operating system;a first security agent embedded in the microcode and a second security agent embedded in the operating system configured to execute the method of claims 1-9.