JP4902129B2

A method and system for enforcing a security policy via a security virtual machine

Abstract

This record has no abstract on file.

Term

Term ended

Expired 25 March 2025, 1.5 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

32 claims: 4 independent, 28 dependent

  1. 1
    A method within a computer device that has a first set of instructions for enforcing a security policy, a step in providing a high-level language security policy, which can cause unwanted behavior. A step indicating system call parameters and a step of compiling the security policy in the high-level language into a security program based on the second instruction set of the security virtual machine, the second of the security virtual machine. The instruction set of is different from the first instruction set of the computer device, and the security virtual machine is implemented using the instructions of the first instruction set of the computer device, the steps and the security program. To the instruction store of the security virtual machine by the computer device and under the control of the operating system running on the computer device in kernel mode. A step of receiving a call to a system call for the operating system, along with parameters, from an application running on the computer device in user mode, which occurs while the application is running outside the security virtual machine. The security enforcement event is the security enforcement event while it is under the control of the security virtual machine by a step and an instruction in the first instruction set that receives the call and is executed by the computer device.To check if it fitsA step of executing the instruction of the second instruction set of the instruction store based on the data of the security execution event including parameters.The instruction in the second instruction set is to confirm whether the parameter contained in the data of the security execution event is indicated in the security policy.And the security implementation event is the security policyFitsWhen this happens, the step of permitting the call of the system call and the security execution event are the security policy.FitsA method comprising a step of blocking a call to the system call when it does not. セキュリティポリシーを実施するための第1の命令セットを有するコンピュータデバイス内の方法であって、 高水準言語のセキュリティポリシーを提供するステップであって、前記セキュリティポリシーは望まない振る舞いを引き起こす可能性のあるシステムコールのパラメータを示す、ステップと、 前記高水準言語の前記セキュリティポリシーをセキュリティプログラムに、セキュリティ仮想マシンの第2の命令セットに基づいてコンパイルするステップであって、前記セキュリティ仮想マシンの前記第2の命令セットは前記コンピュータデバイスの前記第1の命令セットとは異なり、前記セキュリティ仮想マシンは、前記コンピュータデバイスの前記第1の命令セットの命令を使用して実装される、ステップと、 前記セキュリティプログラムを前記セキュリティ仮想マシンの命令ストアに前記コンピュータデバイスによってロードするステップと、 カーネルモードにおける前記コンピュータデバイスで実行するオペレーティングシステムの制御の下で、 ユーザモードにおける前記コンピュータデバイス上で実行するアプリケーションから、パラメータと共に、前記オペレーティングシステムのシステムコールの呼び出しを受け取るステップであって、前記呼び出しは前記セキュリティ仮想マシンの外部でアプリケーションが実行されている間発生するセキュリティ実施イベントである、ステップと、 前記呼び出しを受け取り、前記コンピュータデバイスによって実行される前記第1の命令セットの命令によって前記セキュリティ仮想マシンの制御下にある間、 前記セキュリティ実施イベントが前記セキュリティポリシーに適合するかを確認するためのパラメータを含む前記セキュリティ実施イベントのデータに基づいて、前記命令ストアの前記第2の命令セットの前記命令を実行するステップであって、前記第2の命令セットの前記命令は、前記セキュリティ実施イベントの前記データに含まれる前記パラメータが前記セキュリティポリシーに示されているかどうかを確認することである、ステップと、 前記セキュリティ実施イベントが前記セキュリティポリシーに適合したとき、前記システムコールの呼び出しを許可するステップと、 前記セキュリティ実施イベントが前記セキュリティポリシーに適合しなかったとき、前記システムコールの呼び出しを阻止するステップと を備えることを特徴とする方法。
  2. 12
    Detects when an application running in user mode outside a security virtual machine is making a system call to an operating system running in kernel mode, along with parameters that violate the security policy, running on a computer device. A computer-readable recording medium having a first instruction set that implements the security virtual machine for the purpose, the computer-readable recording medium further having a second instruction set, and the security virtual machine having the security policy. An instruction store containing the instructions of the second instruction set to be implemented, wherein the second instruction set is different from the first instruction set, an instruction store, a data store containing the data of the security policy, and the like. A parameter store containing system call parameters and The system call of the application running outside the security virtual machine by executing the instruction of the instruction store using the data of the data store and the parameters of the parameter store violates the security policy. The operating system in issuing a system call stores the parameters in the parameter store, calls the processor engine, and the processor engine causes the system call to violate the security policy. Allow the system call when it is determined toInstead, the execution of the instruction that implements the security policy generates an action output set that specifies how to handle the security enforcement event, and the action output set implements the security policy in the system call. Instructing the action to be taken for, said action includes notifying the userA computer-readable recording medium characterized by that. コンピュータデバイスによって実行して、セキュリティ仮想マシンの外部においてユーザモードで実行しているアプリケーションがシステムコールをセキュリティポリシーに違反するパラメータと共に、カーネルモードにおいて実行しているオペレーティングシステムへ出しているときを検出するための前記セキュリティ仮想マシンを実装する第1の命令セットを有するコンピュータ可読記録媒体であって、前記コンピュータ可読記録媒体はさらに第2の命令セットを有し、前記セキュリティ仮想マシンは、 前記セキュリティポリシーを実装する前記第2の命令セットの命令を含む命令ストアであって、前記第2の命令セットは前記第1の命令セットとは異なる、命令ストアと、 前記セキュリティポリシーのデータを含むデータストアと、 システムコールのパラメータを含むパラメータストアと、 前記命令ストアの前記命令を、前記データストアのデータおよび前記パラメータストアのパラメータを使用して実行して、前記セキュリティ仮想マシンの外部において実行している前記アプリケーションの前記システムコールが前記セキュリティポリシーに違反するかどうかを判断するプロセッサエンジンと を備え、システムコールの発行における前記オペレーティングシステムは、前記パラメータストアにパラメータを保存し、前記プロセッサエンジンを呼び出し、前記プロセッサエンジンによって前記システムコールが前記セキュリティポリシーに違反することが判定されたとき前記システムコールを許可せず、前記セキュリティポリシーを実装する前記命令の実行は、前記セキュリティ実施イベントをどのように処理するかを指定するアクション出力セットを生成し、アクション出力セットは前記システムコールにおいて前記セキュリティポリシーを実施するために実行されるべきアクションを指示し、前記アクションはユーザに通知することを含むことを特徴とするコンピュータ可読記録媒体。
  3. 26
    Instructions for enforcing a security policyButAn encoded computer-readable recording medium in which the instructions are intended to be executed by a security virtual machine, compiled from the high-level language representation of the security policy, and not executed inside the security virtual machine. When attempting to perform an operation that needs to be verified to compile with the security policy, the instruction must be executed by the security virtual machine running on the computer device and the operating system must verify the application. When it detects that it is attempting to perform an action, the operating system uses the security virtual machine and the action uses the security policy.Does it fitWhen the security virtual machine indicates that the operation does not conform to the security policy, the operating system does not allow the operation to be performed, and the security virtual machine causes the operation to perform the operation. A computer-readable recording medium, characterized in that the operating system allows the operation to be performed when it indicates compliance with a security policy. セキュリティポリシーを実施するための命令が符号化されたコンピュータ可読記録媒体であって、前記命令はセキュリティ仮想マシンによる実行のためのものであり、前記セキュリティポリシーの高水準言語表現からコンパイルされ、セキュリティ仮想マシン内部で実行されていないアプリケーションが前記セキュリティポリシーとともにコンパイルすることを確認される必要がある動作の実行を試みるとき前記命令はコンピュータデバイス上で実行している前記セキュリティ仮想マシンによって実行され、オペレーティングシステムが前記アプリケーションが確認される必要がある動作の実行を試みていることを検出したとき、前記オペレーティングシステムは前記セキュリティ仮想マシンを使用して前記動作が前記セキュリティポリシーに適合するかを決定し、前記セキュリティ仮想マシンが、前記動作が前記セキュリティポリシーに適合しないことを示すとき、前記オペレーティングシステムは前記動作が実行されることを許可せず、前記セキュリティ仮想マシンが、前記動作が前記セキュリティポリシーに適合することを示すとき、前記オペレーティングシステムは前記動作が実行されることを許可することを特徴とするコンピュータ可読記録媒体。
  4. 32
    A method within a computer device that has a first set of instructions for enforcing a security policy, a step in providing a high-level language security policy, which can cause unwanted behavior. Indicates system call parameters, the security policy is compiled from the high-level language into a security program based on the security virtual machine's second instruction set, and the security virtual machine's second instruction set is for the computer device. Unlike the first instruction set, the security virtual machine is implemented using the instructions of the first instruction set of the computer device, which are executed directly by the central processing unit of the computer device. , The step of loading the security program into the instruction store of the security virtual machine by the computer device, and On the computer device in user mode, under the control of the operating system, implemented using the instructions in the first instruction set of the computer device, which is executed directly by the central processor of the computer device in kernel mode. A step of receiving a call to a system call of the operating system from an application to be executed in, which is a security enforcement event that occurs while the application is running, and the application is a central processing device of the computer device. Receiving the steps and the invocations of the system calls of the operating system, which are implemented using the instructions of the first instruction set of the computer device executed directly by, and the execution of the security virtual machine in kernel mode. Is started and the security enforcement event is the security policy while the security virtual machine is running in kernel mode.To check if it fitsA step of executing the instruction of the second instruction set of the instruction store based on the data of the security execution event including parameters.The instruction in the second instruction set is to confirm whether the parameter contained in the data of the security execution event is indicated in the security policy.After the execution of the security virtual machine is stopped, the security execution event is the security policy.FitsWhen the system call is executed, the security execution event is the security policy.FitsA method comprising a step of blocking the execution of the system call when the system call is not executed. セキュリティポリシーを実施するための第1の命令セットを有するコンピュータデバイス内の方法であって、 高水準言語のセキュリティポリシーを提供するステップであって、前記セキュリティポリシーは望まない振る舞いを引き起こす可能性のあるシステムコールのパラメータを示し、前記セキュリティポリシーはセキュリティ仮想マシンの第2の命令セットに基づいて前記高水準言語からセキュリティプログラムへコンパイルされ、前記セキュリティ仮想マシンの前記第2の命令セットは前記コンピュータデバイスの前記第1の命令セットとは異なり、前記セキュリティ仮想マシンは、前記コンピュータデバイスの中央処理装置によって直接実行される前記コンピュータデバイスの前記第1の命令セットの命令を使用して実装される、ステップと、 前記セキュリティプログラムを前記セキュリティ仮想マシンの命令ストアに前記コンピュータデバイスによってロードするステップと、 カーネルモードにおける前記コンピュータデバイスの中央処理装置によって直接実行される前記コンピュータデバイスの前記第1の命令セットの命令を使用して実装される、オペレーティングシステムの制御の下で、 ユーザモードにおける前記コンピュータデバイス上で実行するアプリケーションから、パラメータと共に、前記オペレーティングシステムのシステムコールの呼び出しを受け取るステップであって、前記アプリケーションが実行されている間発生するセキュリティ実施イベントであり、前記アプリケーションは前記コンピュータデバイスの中央処理装置によって直接実行される前記コンピュータデバイスの前記第1の命令セットの命令を使用して実装される、ステップと、 前記オペレーティングシステムの前記システムコールの前記呼び出しを受け取り、カーネルモードにおける前記セキュリティ仮想マシンの実行を開始し、 カーネルモードにおいて前記セキュリティ仮想マシンが実行されている間、前記セキュリティ実施イベントが前記セキュリティポリシーに適合するかどうかを確認するためのパラメータを含む前記セキュリティ実施イベントのデータに基づいて前記命令ストアの前記第2の命令セットの前記命令を実行するステップであって、前記第2の命令セットの前記命令は、前記セキュリティ実施イベントの前記データに含まれる前記パラメータが前記セキュリティポリシーに示されているかどうかを確認することである、ステップと、 前記セキュリティ仮想マシンの実行が停止したのち、 前記セキュリティ実施イベントが前記セキュリティポリシーに適合したとき、前記システムコールを実行するステップと、 前記セキュリティ実施イベントが前記セキュリティポリシーに適合しなかったとき、前記システムコールの実行を阻止するステップと を備えることを特徴とする方法。