Method for preventing malicious software from execution within computer system
Abstract
[Subject] The method for preventing execution of malicious software within computer systems is indicated. [Solution means] In order to bring about the sequence of the command rearranged before what kind of actual execution of an application program with computer systems, permutation is performed about the subset of a command within an application program. It is stored in the instruction pointer table in which the permutation sequence number of the sequence of the rearranged command was rearranged. According to the permutation sequence number of the sequence of the rearranged command which was stored in the instruction pointer table in which the sequence of the rearranged command was rearranged, In the execution module which can translate the sequence of the command rearranged into the actual machine code of the processor, it performs within computer systems. [Selection figure] Fig. 1

Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
36 claims: 6 independent, 30 dependent
- 1A method for preventing the execution of malicious software in a computer system, the application being used to result in a sequence of instructions sorted prior to any actual execution of the application program in the computer system. A step of ordering a subset of instructions in a program, a step of storing the sequence sequence number of the sorted instruction sequence in the sorted instruction pointer table, and the sorted instruction pointer table. In an execution module in the computer system that can translate the sequence of the sorted instructions into the actual machine code of the processor according to the sequence sequence number of the sequence of the sorted instructions stored in. A method consisting of steps to execute a sequence of sorted instructions. コンピューター・システム内で悪意あるソフトウェアの実行を防止するための方法であって、 前記コンピューター・システムでアプリケーション・プログラムの如何なる実際の実行よりも前に並べ替えられた命令のシーケンスをもたらすために前記アプリケーション・プログラム内で命令のサブセットについて順列を行うステップと、 前記並べ替えられた命令のシーケンスの順列シーケンス番号を並べ替えられた命令ポインター・テーブルに格納するステップと、 前記並べ替えられた命令ポインター・テーブルに格納された前記並べ替えられた命令のシーケンスの前記順列シーケンス番号にしたがって、前記並べ替えられた命令のシーケンスをプロセッサーの実際のマシン・コードに翻訳できる前記コンピューター・システム内の実行モジュールにおいて、前記並べ替えられた命令のシーケンスを実行するステップとからなる方法。
- 7A medium that can be used by a computer that has a computer program to prevent the execution of malicious software in the computer system, sorted before any actual execution of the application program in the computer system. A program code means for ordering a subset of instructions within the application program to provide a sequence of instructions, and an instruction pointer table with the sequence sequence numbers of the sorted sequence of instructions sorted. The sequence of the sorted instructions is processed according to the program code means for storing in and the sequence number of the sequence of the sorted instructions stored in the sorted instruction pointer table. A computer-usable medium consisting of program code means for executing the sequence of the sorted instructions in an execution module in the computer system that can be translated into the actual machine code of the computer. コンピューター・システム内で悪意あるソフトウェアの実行を防止するためのコンピューター・プログラムを有するコンピューターに使用可能な媒体であって、 前記コンピューター・システムでアプリケーション・プログラムの如何なる実際の実行よりも前に並べ替えられた命令のシーケンスをもたらすために前記アプリケーション・プログラム内で命令のサブセットについて順列を行うためのプログラム・コード手段と、 前記並べ替えられた命令のシーケンスの順列シーケンス番号を並べ替えられた命令ポインター・テーブルに格納するためのプログラム・コード手段と、 前記並べ替えられた命令ポインター・テーブルに格納された前記並べ替えられた命令のシーケンスの前記順列シーケンス番号にしたがって、前記並べ替えられた命令のシーケンスをプロセッサーの実際のマシン・コードに翻訳できる前記コンピューター・システム内の実行モジュールにおいて、前記並べ替えられた命令のシーケンスを実行するためのプログラム・コード手段とからなるコンピューターに使用可能な媒体。
- 13A computer system capable of preventing the execution of malicious software, the application program to provide a sequence of instructions sorted prior to any actual execution of the application program on the computer system. A means for ordering a subset of instructions within, a sorted instruction pointer table for storing the sequence sequence number of the sequence of the sorted instructions, and the sorted instruction pointer table. In an execution program that can translate the sequence of the sorted instructions into the actual machine code of the processor in the computer system according to the sequence sequence number of the sequence of the sorted instructions stored in. A computer system consisting of a means for executing a sequence of sorted instructions. 悪意あるソフトウェアの実行を防止することができるコンピューター・システムであって、 前記コンピューター・システムでアプリケーション・プログラムの如何なる実際の実行よりも前に並べ替えられた命令のシーケンスをもたらすために前記アプリケーション・プログラム内で命令のサブセットについて順列を行うための手段と、 前記並べ替えられた命令のシーケンスの順列シーケンス番号を格納するための並べ替えられた命令ポインター・テーブルと、 前記並べ替えられた命令ポインター・テーブルに格納された前記並べ替えられた命令のシーケンスの前記順列シーケンス番号にしたがって、前記並べ替えられた命令のシーケンスを前記コンピューター・システム内でプロセッサーの実際のマシン・コードに翻訳できる実行モジュールにおいて、前記並べ替えられた命令のシーケンスを実行するための手段とからなるコンピューター・システム。
- 19A method to prevent the execution of malicious software in a computer system, which is a cross-compiled set of code of the application program prior to any actual execution of the application program in the computer system. In an execution module that can cross-compile the application program to bring about and recognize and translate the cross-compiled set of code of the application program into the actual machine code of the processor in the computer system. A method consisting of steps to execute a cross-compiled set of code for an application program. コンピューター・システム内で悪意あるソフトウェアの実行を防止するための方法であって、 前記コンピューター・システムでアプリケーション・プログラムの如何なる実際の実行よりも前に前記アプリケーション・プログラムのクロスコンパイルされたコードのセットをもたらすために前記アプリケーション・プログラムをクロスコンパイルするステップと、 前記コンピューター・システムでプロセッサーの実際のマシン・コードに前記アプリケーション・プログラムのクロスコンパイルされたコードのセットを認識し、翻訳できる実行モジュールにおいて、前記アプリケーション・プログラムのクロスコンパイルされたコードのセットを実行するステップとからなる方法。
- 25A medium that can be used by a computer that has a computer program to prevent the execution of malicious software in the computer system, prior to any actual execution of the application program in the computer system. The program code means for cross-compiling the application program to provide a cross-compiled set of code for the program, and the cross-compiling of the application program to the actual machine code of the processor on the computer system. A computer-usable medium consisting of program code means for executing the cross-compiled code set of the application program in an execution module capable of recognizing and translating the set of code. コンピューター・システム内で悪意あるソフトウェアの実行を防止するためのコンピューター・プログラムを有するコンピューターに使用可能な媒体であって、 前記コンピューター・システムでアプリケーション・プログラムの如何なる実際の実行よりも前に前記アプリケーション・プログラムのクロスコンパイルされたコードのセットをもたらすために前記アプリケーション・プログラムをクロスコンパイルするためのプログラム・コード手段と、 前記コンピューター・システムでプロセッサーの実際のマシン・コードに前記アプリケーション・プログラムの前記クロスコンパイルされたコードのセットを認識し、翻訳できる実行モジュールにおいて、前記アプリケーション・プログラムの前記クロスコンパイルされたコードのセットを実行するためのプログラム・コード手段とからなるコンピューターに使用可能な媒体。
- 31A computer system that can prevent the execution of malicious software, because it provides a cross-compiled set of code for the application program prior to any actual execution of the application program on the computer system. In an executable module that can recognize and translate the cross-compiled set of code of the application program into the actual machine code of the processor in the computer system and the means for cross-compiling the application program. A computer system consisting of a means for executing a cross-compiled set of code of the application program. 悪意あるソフトウェアの実行を防止することができるコンピューター・システムであって、 前記コンピューター・システムでアプリケーション・プログラムの如何なる実際の実行よりも前に前記アプリケーション・プログラムのクロスコンパイルされたコードのセットをもたらすために前記アプリケーション・プログラムをクロスコンパイルするための手段と、 前記コンピューター・システム内でプロセッサーの実際のマシン・コードに前記アプリケーション・プログラムのクロスコンパイルされたコードのセットを認識し、翻訳できる実行モジュールにおいて、前記アプリケーション・プログラムのクロスコンパイルされたコードのセットを実行するための手段とからなるコンピューター・システム。
Independent claims6
39 paragraphs, as filed
The present invention relates generally to avoiding malicious software, and particularly to methods for preventing the execution of malicious software in a computer system.
Malicious software, such as computer viruses, can infiltrate computer systems in a variety of ways. For example, they can invade a computer system via an optical disc that is supposed to be inserted into the computer system or via an email that is supposed to be opened by a user of the computer system. it can. Malicious software causes some problems when run inside a computer system. For example, computer security may be compromised, or files in the computer system may be corrupted.
Some types of malicious software can be easily detected using simple detection techniques such as scanning the search string. However, this form of detection processing is also easily overturned by converting malicious code through compression and encryption, thereby bypassing the scan filter. Another way to detect malicious software is to run the program while trying to prevent malicious behavior while the program is running. This technique, known as behavior blocking, has many drawbacks. Despite attempts to thwart malicious behavior, programs can cause harm to computer systems. In addition, the motion blocking mechanism usually cannot see the entire log of motion for blocking determination. Therefore, the behavioral blocking mechanism may make a suboptimal blocking decision, which means that a harmless program may be blocked while the harmful program is allowed to run.
Yet another way to detect malicious software is to emulate suspicious code within the isolated environment of the computer system so that the computer system is protected from malicious behavior of the suspicious code. .. One drawback of emulation may be that it partially protects the computer system from virus attacks, but it does not protect the computer system itself. In addition, the data can be infected, which leads to destruction in an isolated environment.
<p> Therefore, it is desirable to provide an improved way to prevent the execution of malicious software within a computer system.</p>
<p> According to a preferred embodiment of the invention, a permutation of instructions within an application program results in a sequence of instructions sorted prior to any actual execution of the application program in the computer system. It is done for a subset. The permutation sequence number of the sorted instruction sequence is stored in the sorted instruction pointer table. The sorted instruction sequence is a sequence of sorted instructions stored in the sorted instruction pointer table according to the sequence sequence number of the sorted instruction sequence of the processor in the computer system. It is executed in an execution module that can be translated into actual machine code.</p><p> Also, the computer system cross-compiles the application program to bring about a cross-compiled set of code for the application program before any actual execution of the application program. A cross-compiled set of code for an application program is executed in an execution module that allows the computer system to recognize and translate the cross-compiled set of code for the application program into the actual machine code of the processor.</p>
<p> The present invention provides a method for preventing the execution of malicious software in a computer system. If the VMM (Virtual Computer Manager) maintains a permutation associated with the hash of each sorted application to be executed, even a sampling attack (where the sample sorted application is managed by the attacker). It will not work (even if it is obtained, permuted, virus applied, and sent to carry out the infection).</p>
All features and advantages of the present invention will become apparent in the detailed description below.
The preferred form of use, as well as its purpose and its advantages, as well as the invention itself, will be best understood by reference to the following detailed description of the specific embodiments when reading with the accompanying drawings. ..
There are usually several levels of instruction sets within a computer system. The first (lowest) level is the machine level instruction and the second level is the operating system application binary interface instruction. At the second level, some of the machine-level instructions are extracted to make it easier for the operating system to understand the machine-level instructions. The third level is macro-level instructions, which further extract control of the computer system to allow the application to be easier to program.
Since many techniques have been directed towards the protection of the second and third instruction levels, the present invention is exclusively the first, especially since the first level is the level used by many computer viruses. Directed to protect the level of instruction.
Generally speaking, writing a machine-level program in a computer system that can be run in the computer system without knowing the processor's machine-level instruction set happens, if not impossible. You don't get it. In addition, installing software on a computer system requires software to first understand the instruction set of the installed computer system. Therefore, according to a preferred embodiment of the invention, the application program is first converted into a cross-compiled code set of the application program, and the cross-compiled code set of the application program is then applied. -It is executed in an execution module that can recognize the cross-compiled set of code of the program.
In particular, with reference to FIG. 1, a conceptual diagram of a method for preventing the execution of malicious software in a computer system according to a preferred embodiment of the present invention is shown. As shown, the computer system 10 includes a conversion module 11 and an execution module 12. Any application program that is supposed to run in computer system 10 must go through an installation process. During the installation process, the user of computer system 10 can decide whether the application program should be installed in computer system 10. If the user decides that the application program should be installed in computer system 10, the application program is then sent to conversion module 11, where the application program cross-compiles the application program. Converted to a set of code. The cross-compiled code set of the application program is then executed within Execution Module 12, which can recognize the cross-compiled code set of the application program and translate it into the machine code of the actual processor. The program.
The application program will not be executed by Execution Module 12 without going through the installation process. For example, as shown in Illegal Path 15, the virus program is installed during the installation process, even if the virus program sneaks in under the user's detection and exists in computer system 10 without the user's knowledge. It has not been executed by execution module 12 yet because it has not passed through. As such, computer system 10 is safe from potential harm that may be caused by virus programs.
In fact, the conversion module 11 and the execution module 12 should be independent of each other. Virtually, execution module 12 should be prevented from accepting code from any source other than conversion module 11.
By the way, referring to FIG. 2, a block diagram of a computing environment incorporating a preferred embodiment of the present invention is illustrated. As shown, the computer system 20 includes a hardware structure 21, a virtual computer manager (VMM) or hypervisor 22, and virtual computers 23a-23b. The virtual computers 23a and 23b are preferably installed in separate compartments so that any execution within the virtual computer 23a is independent of the virtual computer 23b and vice versa. The VMM22 controls all communications between the virtual computers 23a and 23b. In addition, the VMM22 can communicate directly with the hardware structure 21. The hardware structure 21 includes known structures such as a processor, a register, a memory management device, a memory element, and an input / output device.
It is possible for the operating system and multiple application programs to run simultaneously in each of the virtual computers 23a-23b. For example, operating system 24 and application program 25 run on virtual computer 23a, while operating system 26 and application program 27 run on virtual computer 23b.
Although not required, operating system 24 may differ from operating system 26. For example, operating system 24 can be an open source Linux operating system, while operating system 26 can be a Windows® operating system created by Microsoft Corporation. Similarly, the underlying processor emulated by the virtual computer 23a may also differ from the underlying processor emulated by the virtual computer 23b. For example, the underlying processor emulated by virtual computer 23a is a Pentium® processor created by Intel Corporation, while the underlying processor emulated by virtual computer 23b is created by International Business Machines Corporation. It can also be a PowerPC® processor.
Each of the virtual computers 23a-23b contains its operating system and associated application programs, but operates at the user level. When VMM22 uses direct execution, VMM22 is in so-called user mode (ie, so-called user mode) so that neither of the virtual computers 23a-23b can directly access the various privileged registers that control the operation of hardware structure 21. , Limited privileges). Rather, all privileged instructions will be trapped in VMM22.
In Figure 2, the virtual computer 23a is shown to include a cross-compiler 28 for initial cross-compilation of application programs, and the virtual computer 23b is an execution module 29 for executing cross-compiled code. Is illustrated to include. Cross-compiling is preferably done via a permutation algorithm and the results are stored in the sorted instruction pointer table 30. The sorted instruction pointer table 30 contains entries for multiple permutation sequences. Each permutation sequence is associated with a cross-compiled set of code in an application program. All permutation sequences in the sorted instruction pointer table 30 need not be different from each other, but tend to be different from each other. In FIG. 2, the sorted instruction pointer table 30 is shown to be placed inside the VMM22, but if the sorted instruction pointer table 30 can be accessed by the virtual computer 23b. It can also be installed in the virtual computer 23a.
The typical way to perform permutations is as follows. First, a subset of instructions, n, is selected from a group of instructions for permutation purposes. Not all instruction permutations are equally useful. For example, the permutation of identification (ID) instructions is completely useless. Therefore, certain machine instructions (such as JUMP instructions) are identified as important instructions and ensure all important instructions that will be sorted.
There are several ways to generate permutations. One method is to utilize a feature-based hash or encryption such that each instruction in the data segment has a different mapping. That is, the mapping is H (A)<sub>l</sub>), H (A<sub>2</sub>), ..., H (A)<sub>i</sub>), Where H is a function-based hash and A is an instruction. The problem with using feature-based hashes or encryption is that from a general compilation point of view, the same instruction may result in different hashes. For example, instruction A<sub>5</sub>And instruction A<sub>9</sub>May be the same command as, but H (A<sub>5</sub>) Is not necessarily H (A<sub>9</sub>) Is not the same.
The other method is to use a different mapping function, P (A). Where P is a permutation and A is an instruction, but P (A) is P<sub>l</sub>(A), P<sub>2</sub>(A), ... P<sub>n</sub>Generate (A). This method is P<sub>l</sub>(J), where J is a given instruction, but should be the same no matter where it occurs in the code segment, resulting in a more predictable cross-compilation result.
Permutation sequences dictate how n, a subset of instructions, is sorted or transformed. Each permutation sequence can be considered as an entry with multiple slots, each slot being to be filled with an instruction number. A random number between 0 and n! -1 is selected first to generate the rth permutation sequence. For example, if n, which is a subset of the instructions needed to be sorted (which means a permutation sequence of 5! = 120), then the random number 101 is 0 and 5! -1 as the 101st permutation sequence. Selected between.
The slot position of the first instruction number, Pos, is represented by the quotient of the selected random number r divided by (n-1) !, and is as follows.
<maths num="1"><img file="JP2007220091A_D0001.tif" /></maths>
The remainder of the split replaces the random number r chosen to determine Pos, which is the slot position of the subsequent instruction number until all slots are filled with the instruction number. For each decision, n in the denominator (n-1)! Is decremented by one.
In this way, for the selected random number 101, the slot position of the first instruction number is 101 / (5-1)! = 4 as shown in FIG. 3a. The remainder of 101 / (5-1)! Is 5, and the slot position of the second instruction number is 5 / (4-1)! = 0 as shown in FIG. 3b. The remainder of 5 / (4-1)! Is 5, and the slot position of the third instruction number is 5 / (3-1)! = 2 as shown in Fig. 3c. The remainder of 5 / (3-1)! Is 1, and the slot position of the 4th instruction number is 1 / (2-1)! = 1 as shown in FIG. 3d. The fifth instruction number is the remaining open slot position as shown in Figure 3e.
The permutation sequence "25431" (from Figure 3e) is then entered into the instruction pointer table 30 (from Figure 2) sorted as an entry for the 101st permutation sequence. The application program is sorted into a cross-compiled set of code via cross-compiler 28 (from Figure 2) according to the 101st permutation sequence. During execution, the cross-compiled set of code is executed via execution module 29 (from Figure 2) according to the 101st permutation sequence stored in the sorted instruction pointer table 30.
For example, if the five instructions selected to be sorted are ADD, SUBTRACT, JUMP, BRANCH and STORE, then each of these instructions is ADD for instruction number 1 and SUBTRACT for instruction number 2. One instruction number is assigned, such as JUMP for number 3, BRANCH for instruction number 4, and STORE for instruction number 5. When the 101st permutation sequence is used to cross-compile the application program within the cross-compiler 28 of Figure 2, each occurrence of the above five instructions in the application program follows the permutation sequence "25431". Will be converted. In other words, each ADD instruction in the application program is converted to a SUBTRACT instruction, each SUBTRACT instruction in the application program is converted to a STORE instruction, and each JUMP instruction in the application program is converted to a BRANCH instruction. Then, each BRANCH instruction in the application program is converted into a JUMP instruction, and each STORE instruction in the application program is converted into an ADD instruction. The reverse of the above conversion is done in the execution module 29 of Figure 2 during the execution of the cross-compiled code of the application program.
The sequence can be done either statically or dynamically. If permutations are done in a static way, groups of computer systems are set to use the same permutation sequence. Such a practice would be easier for information technology managers, as cross-compiling of each application program would only be required to be performed once during installation.
If permutations are done in a dynamic way, there are several choices. The set of permutation sequences can be changed cyclically. Cross-compiling for those permutations can only be done once, and each time the computer system is booted, it actually runs a different set of cross-compiled programs based on the permutations in use. be able to. In addition, the permutation sequence can change irregularly each time the computer system is booted. In such cases, the cross-compilation would have to be done "on the fly" by a cross-compiler running on the computer system.
In addition, permutation sequences can be modified for each application program as well, and the modifications can be made in different ways. The simplest practice is to have the VMM use the application's signature hash as the key to the streaming encryption algorithm, thereby generating a unique set of instructions for that application program. Any modified application program will begin to generate different instruction sets (as modified in main memory by a virus that causes a buffer overflow).
Alternatively, the VMM will generate a random number each time the application program is loaded, and the code segment of the application program will have a hash to modify the streaming encryption or cross-compilation (it does not have to be reversible). It runs through the engine. This method is P<sub>n</sub>(A) The function becomes a constant function P (A), which provides another level of security in that it remains unpredictable.
Although the present invention has been described in the context of a fully functional computer system, the mechanisms of the present invention can be distributed as program products in various forms, and the present invention will actually carry out the distribution. It is also important to note that those skilled in the art appreciate the equal fit regardless of the particular type of signal bearing media used for this purpose. Examples of signal-carrying media include, without limitation, recordable media such as floppy disks and compact discs, and transmission media such as analog or digital communication links.
Although the invention is illustrated and described with reference to particularly preferred embodiments, it will be appreciated by those skilled in the art that various changes in form and detail will be made without departing from the spirit and scope of the invention. ..
<figref num="1">FIG. 5 is a conceptual diagram of a method for preventing the execution of malicious software in a computer system based on a preferred embodiment of the present invention.</figref><figref num="2">FIG. 6 is a block diagram of a computer environment incorporating preferred embodiments of the present invention.</figref><figref num="3">It represents a sequence rearranged in an instruction according to a preferred embodiment of the present invention.</figref>
Code description
10, 20 Computer system 11 Conversion module 12, 29 Execution module 21 Hardware structure 22 Virtual computer manager 23a, 23b Virtual computer 24, 26 Operating system 25, 27 Application program 28 Cross compiler 30 Sorted instruction pointer ·table
1 sheet
Sheet 1
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2000056966A | Cites | Japan | Examiner |
| JP2005085188A | Cites | Japan | Search report |
| JP2005532622A | Cites | Japan | Examiner |
8 priority claims, no other members on record
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 11353893 | United States of America | – | |
| 11353896 | United States of America | – | |
| 35389306 | United States of America | A | |
| 35389606 | United States of America | A | |
| 2006353893 | – | – | – |
| 2006353896 | – | – | – |
| US20060353893 | – | – | – |
| US20060353896 | – | – | – |
21 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Receipt of annual feesR250 | R250 | |
| Receipt of annual feesR250 | R250 | |
| Receipt of annual feesR250 | R250 | |
| Receipt of annual feesR250 | R250 | |
| Receipt of annual feesR250 | R250 | |
| Receipt of annual feesR250 | R250 | |
| Receipt of annual feesR250 | R250 | |
| Receipt of annual feesR250 | R250 | |
| Receipt of annual feesR250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| First payment of annual fees (during grant procedure)A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentA521 | A521 | |
| Notification of reasons for refusalA131 | A131 | |
| Written amendmentA521 | A521 | |
| Notification of reasons for refusalA131 | A131 |
Numbers
- Publication
- 2007220091
- Publication, DOCDB
- 2007220091
- Publication, EPODOC
- JP2007220091
- Application
- 351470
- Application, DOCDB
- 2006351470
- Application, EPODOC
- JP20060351470
Titles3
- English
- METHOD FOR PREVENTING MALICIOUS SOFTWARE FROM EXECUTION WITHIN COMPUTER SYSTEM
- Japanese
- コンピューター・システム内で悪意あるソフトウェアの実行を防止するための方法
- English
- How to prevent malicious software from running in your computer system
Classification
- CPC, 2
- G06F21/561
- G06F21/566
- IPC, 2
- G06F21 56
- G06F21 22