A method and system for enforcing a security policy via a security virtual machine
Abstract
This record has no abstract on file.
Term
Term ended
Expired 25 March 2025, 1.5 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
32 claims: 4 independent, 28 dependent
- 1A method within a computer device that has a first set of instructions for enforcing a security policy, a step in providing a high-level language security policy, which can cause unwanted behavior. A step indicating system call parameters and a step of compiling the security policy in the high-level language into a security program based on the second instruction set of the security virtual machine, the second of the security virtual machine. The instruction set of is different from the first instruction set of the computer device, and the security virtual machine is implemented using the instructions of the first instruction set of the computer device, the steps and the security program. To the instruction store of the security virtual machine by the computer device and under the control of the operating system running on the computer device in kernel mode. A step of receiving a call to a system call for the operating system, along with parameters, from an application running on the computer device in user mode, which occurs while the application is running outside the security virtual machine. The security enforcement event is the security enforcement event while it is under the control of the security virtual machine by a step and an instruction in the first instruction set that receives the call and is executed by the computer device.To check if it fitsA step of executing the instruction of the second instruction set of the instruction store based on the data of the security execution event including parameters.The instruction in the second instruction set is to confirm whether the parameter contained in the data of the security execution event is indicated in the security policy.And the security implementation event is the security policyFitsWhen this happens, the step of permitting the call of the system call and the security execution event are the security policy.FitsA method comprising a step of blocking a call to the system call when it does not. セキュリティポリシーを実施するための第1の命令セットを有するコンピュータデバイス内の方法であって、 高水準言語のセキュリティポリシーを提供するステップであって、前記セキュリティポリシーは望まない振る舞いを引き起こす可能性のあるシステムコールのパラメータを示す、ステップと、 前記高水準言語の前記セキュリティポリシーをセキュリティプログラムに、セキュリティ仮想マシンの第2の命令セットに基づいてコンパイルするステップであって、前記セキュリティ仮想マシンの前記第2の命令セットは前記コンピュータデバイスの前記第1の命令セットとは異なり、前記セキュリティ仮想マシンは、前記コンピュータデバイスの前記第1の命令セットの命令を使用して実装される、ステップと、 前記セキュリティプログラムを前記セキュリティ仮想マシンの命令ストアに前記コンピュータデバイスによってロードするステップと、 カーネルモードにおける前記コンピュータデバイスで実行するオペレーティングシステムの制御の下で、 ユーザモードにおける前記コンピュータデバイス上で実行するアプリケーションから、パラメータと共に、前記オペレーティングシステムのシステムコールの呼び出しを受け取るステップであって、前記呼び出しは前記セキュリティ仮想マシンの外部でアプリケーションが実行されている間発生するセキュリティ実施イベントである、ステップと、 前記呼び出しを受け取り、前記コンピュータデバイスによって実行される前記第1の命令セットの命令によって前記セキュリティ仮想マシンの制御下にある間、 前記セキュリティ実施イベントが前記セキュリティポリシーに適合するかを確認するためのパラメータを含む前記セキュリティ実施イベントのデータに基づいて、前記命令ストアの前記第2の命令セットの前記命令を実行するステップであって、前記第2の命令セットの前記命令は、前記セキュリティ実施イベントの前記データに含まれる前記パラメータが前記セキュリティポリシーに示されているかどうかを確認することである、ステップと、 前記セキュリティ実施イベントが前記セキュリティポリシーに適合したとき、前記システムコールの呼び出しを許可するステップと、 前記セキュリティ実施イベントが前記セキュリティポリシーに適合しなかったとき、前記システムコールの呼び出しを阻止するステップと を備えることを特徴とする方法。
- 12Detects when an application running in user mode outside a security virtual machine is making a system call to an operating system running in kernel mode, along with parameters that violate the security policy, running on a computer device. A computer-readable recording medium having a first instruction set that implements the security virtual machine for the purpose, the computer-readable recording medium further having a second instruction set, and the security virtual machine having the security policy. An instruction store containing the instructions of the second instruction set to be implemented, wherein the second instruction set is different from the first instruction set, an instruction store, a data store containing the data of the security policy, and the like. A parameter store containing system call parameters and The system call of the application running outside the security virtual machine by executing the instruction of the instruction store using the data of the data store and the parameters of the parameter store violates the security policy. The operating system in issuing a system call stores the parameters in the parameter store, calls the processor engine, and the processor engine causes the system call to violate the security policy. Allow the system call when it is determined toInstead, the execution of the instruction that implements the security policy generates an action output set that specifies how to handle the security enforcement event, and the action output set implements the security policy in the system call. Instructing the action to be taken for, said action includes notifying the userA computer-readable recording medium characterized by that. コンピュータデバイスによって実行して、セキュリティ仮想マシンの外部においてユーザモードで実行しているアプリケーションがシステムコールをセキュリティポリシーに違反するパラメータと共に、カーネルモードにおいて実行しているオペレーティングシステムへ出しているときを検出するための前記セキュリティ仮想マシンを実装する第1の命令セットを有するコンピュータ可読記録媒体であって、前記コンピュータ可読記録媒体はさらに第2の命令セットを有し、前記セキュリティ仮想マシンは、 前記セキュリティポリシーを実装する前記第2の命令セットの命令を含む命令ストアであって、前記第2の命令セットは前記第1の命令セットとは異なる、命令ストアと、 前記セキュリティポリシーのデータを含むデータストアと、 システムコールのパラメータを含むパラメータストアと、 前記命令ストアの前記命令を、前記データストアのデータおよび前記パラメータストアのパラメータを使用して実行して、前記セキュリティ仮想マシンの外部において実行している前記アプリケーションの前記システムコールが前記セキュリティポリシーに違反するかどうかを判断するプロセッサエンジンと を備え、システムコールの発行における前記オペレーティングシステムは、前記パラメータストアにパラメータを保存し、前記プロセッサエンジンを呼び出し、前記プロセッサエンジンによって前記システムコールが前記セキュリティポリシーに違反することが判定されたとき前記システムコールを許可せず、前記セキュリティポリシーを実装する前記命令の実行は、前記セキュリティ実施イベントをどのように処理するかを指定するアクション出力セットを生成し、アクション出力セットは前記システムコールにおいて前記セキュリティポリシーを実施するために実行されるべきアクションを指示し、前記アクションはユーザに通知することを含むことを特徴とするコンピュータ可読記録媒体。
- 26Instructions for enforcing a security policyButAn encoded computer-readable recording medium in which the instructions are intended to be executed by a security virtual machine, compiled from the high-level language representation of the security policy, and not executed inside the security virtual machine. When attempting to perform an operation that needs to be verified to compile with the security policy, the instruction must be executed by the security virtual machine running on the computer device and the operating system must verify the application. When it detects that it is attempting to perform an action, the operating system uses the security virtual machine and the action uses the security policy.Does it fitWhen the security virtual machine indicates that the operation does not conform to the security policy, the operating system does not allow the operation to be performed, and the security virtual machine causes the operation to perform the operation. A computer-readable recording medium, characterized in that the operating system allows the operation to be performed when it indicates compliance with a security policy. セキュリティポリシーを実施するための命令が符号化されたコンピュータ可読記録媒体であって、前記命令はセキュリティ仮想マシンによる実行のためのものであり、前記セキュリティポリシーの高水準言語表現からコンパイルされ、セキュリティ仮想マシン内部で実行されていないアプリケーションが前記セキュリティポリシーとともにコンパイルすることを確認される必要がある動作の実行を試みるとき前記命令はコンピュータデバイス上で実行している前記セキュリティ仮想マシンによって実行され、オペレーティングシステムが前記アプリケーションが確認される必要がある動作の実行を試みていることを検出したとき、前記オペレーティングシステムは前記セキュリティ仮想マシンを使用して前記動作が前記セキュリティポリシーに適合するかを決定し、前記セキュリティ仮想マシンが、前記動作が前記セキュリティポリシーに適合しないことを示すとき、前記オペレーティングシステムは前記動作が実行されることを許可せず、前記セキュリティ仮想マシンが、前記動作が前記セキュリティポリシーに適合することを示すとき、前記オペレーティングシステムは前記動作が実行されることを許可することを特徴とするコンピュータ可読記録媒体。
- 32A method within a computer device that has a first set of instructions for enforcing a security policy, a step in providing a high-level language security policy, which can cause unwanted behavior. Indicates system call parameters, the security policy is compiled from the high-level language into a security program based on the security virtual machine's second instruction set, and the security virtual machine's second instruction set is for the computer device. Unlike the first instruction set, the security virtual machine is implemented using the instructions of the first instruction set of the computer device, which are executed directly by the central processing unit of the computer device. , The step of loading the security program into the instruction store of the security virtual machine by the computer device, and On the computer device in user mode, under the control of the operating system, implemented using the instructions in the first instruction set of the computer device, which is executed directly by the central processor of the computer device in kernel mode. A step of receiving a call to a system call of the operating system from an application to be executed in, which is a security enforcement event that occurs while the application is running, and the application is a central processing device of the computer device. Receiving the steps and the invocations of the system calls of the operating system, which are implemented using the instructions of the first instruction set of the computer device executed directly by, and the execution of the security virtual machine in kernel mode. Is started and the security enforcement event is the security policy while the security virtual machine is running in kernel mode.To check if it fitsA step of executing the instruction of the second instruction set of the instruction store based on the data of the security execution event including parameters.The instruction in the second instruction set is to confirm whether the parameter contained in the data of the security execution event is indicated in the security policy.After the execution of the security virtual machine is stopped, the security execution event is the security policy.FitsWhen the system call is executed, the security execution event is the security policy.FitsA method comprising a step of blocking the execution of the system call when the system call is not executed. セキュリティポリシーを実施するための第1の命令セットを有するコンピュータデバイス内の方法であって、 高水準言語のセキュリティポリシーを提供するステップであって、前記セキュリティポリシーは望まない振る舞いを引き起こす可能性のあるシステムコールのパラメータを示し、前記セキュリティポリシーはセキュリティ仮想マシンの第2の命令セットに基づいて前記高水準言語からセキュリティプログラムへコンパイルされ、前記セキュリティ仮想マシンの前記第2の命令セットは前記コンピュータデバイスの前記第1の命令セットとは異なり、前記セキュリティ仮想マシンは、前記コンピュータデバイスの中央処理装置によって直接実行される前記コンピュータデバイスの前記第1の命令セットの命令を使用して実装される、ステップと、 前記セキュリティプログラムを前記セキュリティ仮想マシンの命令ストアに前記コンピュータデバイスによってロードするステップと、 カーネルモードにおける前記コンピュータデバイスの中央処理装置によって直接実行される前記コンピュータデバイスの前記第1の命令セットの命令を使用して実装される、オペレーティングシステムの制御の下で、 ユーザモードにおける前記コンピュータデバイス上で実行するアプリケーションから、パラメータと共に、前記オペレーティングシステムのシステムコールの呼び出しを受け取るステップであって、前記アプリケーションが実行されている間発生するセキュリティ実施イベントであり、前記アプリケーションは前記コンピュータデバイスの中央処理装置によって直接実行される前記コンピュータデバイスの前記第1の命令セットの命令を使用して実装される、ステップと、 前記オペレーティングシステムの前記システムコールの前記呼び出しを受け取り、カーネルモードにおける前記セキュリティ仮想マシンの実行を開始し、 カーネルモードにおいて前記セキュリティ仮想マシンが実行されている間、前記セキュリティ実施イベントが前記セキュリティポリシーに適合するかどうかを確認するためのパラメータを含む前記セキュリティ実施イベントのデータに基づいて前記命令ストアの前記第2の命令セットの前記命令を実行するステップであって、前記第2の命令セットの前記命令は、前記セキュリティ実施イベントの前記データに含まれる前記パラメータが前記セキュリティポリシーに示されているかどうかを確認することである、ステップと、 前記セキュリティ仮想マシンの実行が停止したのち、 前記セキュリティ実施イベントが前記セキュリティポリシーに適合したとき、前記システムコールを実行するステップと、 前記セキュリティ実施イベントが前記セキュリティポリシーに適合しなかったとき、前記システムコールの実行を阻止するステップと を備えることを特徴とする方法。
Independent claims4
31 paragraphs, as filed
The present invention generally relates to enforcing security policies to block unwanted behavior by computer programs.
Software systems, such as operating systems and file systems, provide an application programming interface through which application programs can access the services of the software system. The application program interface can provide functions with parameters to execute the specified service. For example, a file system can have a function (also called a "system call") for creating a file. The function can have parameters that specify the file location, file name, file type, file size, etc. of the created file. When the application program calls a function, it passes the actual parameters that correspond to the formal parameters defined for the function. The function can perform certain checks on the actual parameters to ensure that those parameters are valid. For example, a file creation function can guarantee that the specified file type is valid. If the parameter is not valid, the function returns the error to the application program.
Software systems can be extremely complex for a variety of reasons. A software system may attempt to be backward compatible with all previous versions of that software system. In such cases, the software system may need to support all functions of the previous version of the application program interface. Since new functions are usually added to each version, the number of functions can be very large and the interaction of functions can be complicated. Some software systems may also contain software components developed by different departments of the same company or by different companies. The interaction of these components can also be very complex.
<p> It is becoming increasingly important for software systems to ensure that their application programming interfaces are not vulnerable to either inadvertent misuse or intentional attack. One vulnerability in a software system may be through a parameter in its application programming interface. When an earlier version of a function is combined with a newer version of the function, or when components from different developers are integrated, validation of existing parameters performed by the function will ensure that the function behaves correctly. It may not be enough to guarantee. For example, a file system application programming interface developed by one company may be integrated with a file server developed by another company. The maximum file size parameter of the application programming interface may be larger than the size supported by the file server. In such cases, the file size applicable to the application programming interface can cause problems with the file server. As another example, a system administrator may want to limit the maximum file size even further, but the system administrator may not have the means available to enforce that limit. There is.</p><p> It would be desirable to have a security policy, and in particular a mechanism for enforcing a security policy that specifies valid conditions for the parameters of the application program interface.</p>
<p> A security virtual machine provides a method and system for enforcing a security policy. Security virtual machines include a processor engine, an instruction store, a data store and an instruction pointer. The security virtual engine runs a specified security program using an intermediate language compiled from a high-level language representation of a security policy. The security program is loaded into the instruction store for execution. When a security enforcement event occurs, such as an application programming interface function call, the data from the security enforcement event is stored in the datastore and the processor engine begins fetching and executing instructions for the security program from the instruction store. To do. The instruction specifies the action to be taken to enforce the security policy, based on the data of the security enforcement event.</p>
Security Provides methods and systems in computer systems for enforcing encoded security policies within a virtual machine's instruction set. In one embodiment, the security system provides a security virtual machine that executes a security program represented within the security virtual machine's instruction set (ie, an intermediate language). A security system can include a compiler that receives a security policy expressed in a high-level language and generates a security program that is an expression of the security policy in the intermediate language of a security virtual machine. The security system stores the security program in the instruction store of the security virtual machine. When a security enforcement event occurs (ie, an action that needs to be checked to ensure that it compiles with the security policy), the security virtual machine uses the data from the security enforcement event to store its instructions. Execute the command for the security program from and implement the security policy. If a security enforcement event indicates that an attempt is being made to perform an undesired behavior (eg, an action that could exploit an operating system vulnerability), the security program blocks the attempt. be able to. In one embodiment, the security virtual machine of the security system runs in kernel mode of the operating system and attempts by applications and external systems to perform undesired behavior for the computer system on which the security system is running. To identify and prevent.
In one embodiment, the security system identifies when the parameters of a system call issued by an application to a system service (eg, a file system and a memory management system) can lead to undesired behavior. A security policy contains conditions based on system call parameters and rules that specify actions to take when the conditions are met. For example, the conditions of a rule may be met when a file creation system call is issued with a parameter that specifies a file size greater than 1GB. The action associated with that rule can be made to block the creation of the file. High-level languages can be XML-based languages, and each rule can be identified by rules, conditions, and action tags. When the rules of a security policy expressed in a high-level language are compiled, each rule is translated into an intermediate language instruction to form a security program. For example, a rule can be transformed into a set of instructions. Print a system call to compare a value indicating that the function is "create file", a file size parameter to a constant with a value of 1GB, and instructions to block the system call. It is a thing.
In one embodiment, the security virtual machine includes a processor engine, an instruction store, an instruction pointer and a data store. When you initialize a security virtual machine and enforce a security policy, the security system loads the instruction store with a security program that enforces the security policy. The security system also loads the security program data into the data store. When a system call is received, the security system stores the system call parameters (including values that identify the system call) in the data store. The security system can also store process control information for the process that issued the system call in the data store. The security system initializes the instruction pointer to point to the instruction to start the security program. The processor engine starts a security program by fetching and executing the start instruction pointed to by the instruction pointer. Each instruction to be executed modifies the instruction pointer to point to the next instruction to be executed. The instruction refers to the data in the data store and enforces the security policy. Execution of a security program produces an output action set that specifies the actions that should be taken to enforce the security policy (eg, blocking system calls).
In one embodiment, the security policy can include a sub-policy for each system call whose parameters should be checked. The security system can compile each subpolicy into a separate security subprogram, and these separate security subprograms can be loaded into the instruction store independently of the other security subprograms. Each subpolicy may correspond to a security enforcement for a single system call. The security system can maintain a mapping of each system call to the start instruction pointer in the instruction store and to the start data pointer to the data in the data store of the corresponding security subprogram. When implementing a security policy in a system call, the security system initializes the instruction pointer to the corresponding start instruction pointer and the data pointer to the corresponding start data pointer. Security subprograms can use instruction and data reference techniques related to instruction pointers and data pointers. In this way, the instructions and data of each security subprogram can be rearranged. In the following description, a single security program handles all system calls by decoding each system call and jumping to the appropriate instruction location to handle that system call. It will be appreciated by those skilled in the art that this described system can be adapted to support subprograms for each system call.
FIG. 1 is a block diagram illustrating the components of the security system of one embodiment. The security system includes some components that run in user mode 100 and other components that run in kernel mode 120. Policy compiler 102 is a component that runs in user mode and compiles the security policy of policy store 103 into a security program that can be executed by a security virtual machine. Kernel mode components include a system call intercept component 121, a program load component 122, and a security virtual machine 125. The security virtual machine includes an instruction pointer 126, a processor engine 127, an instruction store 128, and a data store 129. The program load component loads the security program compiled by the policy compiler into the instruction store of the security virtual machine, stores the program data in the data store, and sets the start instruction pointer. The system call intercept component intercepts the system call issued by the application program 101, and stores the parameters of each system call and the process control information of the application program in the data store. After intercepting the system call and storing its parameters, the system call intercept component instructs the processor engine to execute the instruction store security program. The processor engine executes a security program by fetching the instruction pointed to by the instruction pointer and performing the operation specified by the instruction. The operation involves storing the actions to be taken to enforce the security policy in the datastore's output action set. Security
Computing devices that implement security systems include central processing units, memory, input devices (eg keyboards and pointing devices), output devices (eg display devices), and storage devices (eg disk drives). Can be done. A memory and storage device is a computer-readable medium that can contain instructions that implement a security system. In addition, data structures and message structures can be stored or transmitted via data transmission media such as signals on communication links. Various communication links can be used, such as the Internet, local area networks, wide area networks, or point-to-point dial-up connections.
Figure 1 illustrates an example of a suitable operating environment in which a security system can be implemented. This operating environment is only one embodiment of a suitable operating environment and is not intended to imply any limitation on the use or scope of functionality of the security system. Other well-known computing systems, environments and configurations that may be suitable for use include personal computers, server computers, handheld or laptop devices, multiprocessor systems, microprocessor-based systems, programmable consumer electronics, etc. Includes networked PCs, minicomputers, mainframe computers, distributed computing environments that include any of the above systems or devices, and more.
Security systems can generally be described in relation to computer executable instructions executed by one or more computers or other devices, such as program modules. Program modules typically include routines, programs, objects, components, data structures, etc., which either perform a particular task or implement a particular abstract data type. Generally, the functionality of a program module can be combined or distributed as desired in various embodiments.
FIG. 2 is a block diagram illustrating the data structure of the data store of one embodiment. The data store includes a literal data structure 201, a dynamic data structure 211, a system call parameter data structure 221, a process control block data structure 231 and an action output set 241. The literal data structure includes a literal data table 202 and a literal data store 203. The literal data table contains fixed-size entries that reference literal data stored in the literal data store. "Literal data" refers to data in a security program that is constant during the life of the currently loaded security policy. Literal data can only be modified by loading a new security policy. Dynamic data structures have a similar organization to literal data structures, but store "dynamic" data rather than "literal data". "Dynamic data" refers to security program data that can be modified without loading a new security policy. For example, dynamic data may contain the names of applications that are exempt from security policies. Each entry in the literal and dynamic data tables points to the data in the corresponding data store. Data in literal and dynamic data stores is represented in a self-describing format. The format contains data type and data size information. In one embodiment, the security virtual machine supports Boolean, integer, string and raw binary (also called "blobs") data types in addition to arrays of integers, strings and blobs. The instruction references literal and dynamic data using indexes on literal and dynamic tables. When executing an instruction, the security virtual machine searches for indexes on literal and dynamic tables, and its values for data items in literal or dynamic data stores. Dereference by using it as a pointer to the start. Since the data is self-describing, the type and size of the data can be determined. The system call parameter data structure includes a string table 222, an integer table 223, and a raw binary table 224. System call parameters are stored in these tables according to their data type. A process control block data structure is a table containing entries for each piece of process control information available to a security virtual machine. In one embodiment, the process control information includes an application identifier and a thread identifier. An action output set can be a set of action flags that are generated during the execution of a security program and dictate the actions that should be taken to enforce the security policy in a system call. Actions may include blocking system calls and notifying the user. , Can be a set of action flags. Actions may include blocking system calls and notifying the user. , Can be a set of action flags. Actions may include blocking system calls and notifying the user.
FIG. 3 is a diagram illustrating the layout of the instructions of the security virtual machine of one embodiment. Each instruction includes an operation field 310, a parameter 1 field 320, a true branch field 330, a false branch field 340, and a parameter 2 field 350. The parameter 1 field is the data associated with the system call (ie, stored within the system call data structure or process control data structure) and the parameter 2 field reference data associated with the security program (ie, literal). Or refer to immediate data or data stored in a dynamic data structure). The operation field contains parameter 2 descriptor 311 (m) and operation code 312. The Parameter 2 descriptor specifies how to interpret Parameter 2. Parameter 2 (also called p2) can include a reference to immediate data, a reference to dynamic data, or a reference to literal data. When a reference is specified, the security virtual machine dereferences parameter 2 before performing the operation of the instruction. The operation code identifies the operation of the instruction, as defined in more detail below. The Parameter 1 field contains the Parameter 1 descriptor 321 (s) and the index 322. The parameter 1 descriptor indicates whether parameter 1 refers to system call parameters or process control information. If the parameter 1 descriptor points to a system call parameter, the high-order bits of the index should be indexed on the string table of the system call parameter data structure or on the integer table. , Specifies whether the raw binary table should be indexed, the lower bits indicate the indexed entry of the table. If the parameter 1 descriptor points to process control information, the index is the specific process control. Instruct information. True and false branching fields contain offsets that specify the next instruction to execute, depending on whether the condition code for this instruction evaluates to be true or false. The offset is added to the current instruction pointer to point to the next instruction to be executed.
Tables 1 and 2 illustrate the instructions for the security virtual machine of one embodiment. Instructions can be categorized as those that perform tests on the data and those that do not. Table 1 exemplifies non-test instructions.
<tables num="1"><img file="JP4902129B2_D0001.tif" /></tables>
Table 2 exemplifies the test instructions. The pattern instruction can define a regular expression to compare two strings, which is useful for wildcard type comparisons of filenames (eg "* .DAT").
<tables num="2"><img file="JP4902129B2_D0002.tif" /></tables>
FIG. 4 is a flow chart illustrating the processing of the program load component of one embodiment. The component is called when the security program should be loaded into the security virtual machine. Security programs include virtual instructions, literal data blocks, and dynamic data blocks. The literal data block contains information in the literal data table followed by information in the literal data store. The component starts the literal data block at the starting point and copies it to the literal store. The component then adds its base location to each offset in the literal data table and converts the offset to a pointer. Components process dynamic data blocks in a similar way. Virtual instructions include multiple offsets to the start of literal and dynamic stores. At block 401, the component identifies the starting location in the literal store, starts at that starting location, and copies the literal data block of the security program. At block 402, the component adds a starting location to each offset in the literal data table and converts the security program offset into a pointer. At block 403, the component identifies the starting location in the dynamic store and starts at that starting location to copy the dynamic data block of the security program. At block 404, the component adds a starting location to each offset in the dynamic data table and converts the security program offset into a pointer. At block 405, the component copies the security program's virtual instructions to the instruction store and then compiles them.
FIG. 5 is a flow chart illustrating the processing of the system call intercept component of one embodiment. The component is called when the system call is intercepted. The component initializes the system call parameter data structure and process control data structure, and then starts the security virtual machine. The component can also provide instruction pointers for instructions to initiate execution and process system calls. When a security subprogram is used, a component can have mappings of system calls to start instruction pointers and to start data pointers to literal and dynamic data structures for that system call. You can call the program load component multiple times to load different subprograms of your security program to handle different system calls. Because the instructions and data are offset-based, the instructions and data can be stored in the next available location after the instruction store and data structure. At block 501, the component sets the current instruction pointer (also called ip) to the start instruction pointer of the security program and resets the action output set to its initial state (eg, empty). In blocks 502 to 504, the component loops while storing the system call parameters in the system call parameter data structure. At block 502, the component selects the following parameters for the system call: In decision block 503, if all parameters of the system call are already selected, the component follows block 505, otherwise the component follows block 504. At block 504, the component stores the selected parameters in the appropriate table of the system call parameter data structure and then loops into block 502 to select the next parameter for the system call. In blocks 505 ~ 507, component Loops while storing string process control information in the process control data structure. At block 505, the component selects the next process control information for the process that made the system call. In decision block 506, if all process control information is already selected, the component follows block 508, otherwise the component follows block 507. At block 507, the component stores the selected process control (also called pc) information in the process control data structure and then loops into block 505 to select the next process control information. Alternatively, instead of using and initializing internal process control data structures, the security system can retrieve process control information directly from the process control block when needed. Those skilled in the art will appreciate that process control blocks are created by the operating system when a process is created. At block 508, the component launches a security virtual machine (also known as vm) to enforce the security policy on the intercepted system call. After the security program has been executed by the security virtual machine, the component executes the actions in the action output set. Store and then loop into block 505 to select the next process control information. Alternatively, instead of using and initializing internal process control data structures, the security system can retrieve process control information directly from the process control block when needed. Those skilled in the art will appreciate that process control blocks are created by the operating system when a process is created. At block 508, the component launches a security virtual machine (also known as vm) to enforce the security policy on the intercepted system call. After the security program has been executed by the security virtual machine, the component executes the actions in the action output set. Store and then loop into block 505 to select the next process control information. Alternatively, instead of using and initializing internal process control data structures, the security system can retrieve process control information directly from the process control block when needed. Those skilled in the art will appreciate that process control blocks are created by the operating system when a process is created. At block 508, the component launches a security virtual machine (also known as vm) to enforce the security policy on the intercepted system call. After the security program has been executed by the security virtual machine, the component executes the actions in the action output set.
FIG. 6 is a flow chart illustrating the processing of the processor engine of the security virtual machine of one embodiment. The processor engine initializes the system call parameter data structure based on the intercepted system call, launches the security virtual machine, and performs the actions of the output action set. In blocks 601 to 607, the processor engine loops while loading and executing the instructions of the security program stored in the instruction store until the stop instruction is executed. In one embodiment, a security policy can define that no other rule is tested whenever the conditions of the rule are met. At block 601, the processor engine fetches the instruction pointed to by the current instruction pointer. At block 602, the processor engine calls the component to dereference parameter 1 and parameter 2. In decision block 603, if the instruction operation code is a test operation, the processor engine follows block 604. If the instruction's operation code is a non-test operation (except for a stop operation), the processor engine follows block 608. If the operation code of the instruction is a stop operation, the processor engine continues to block 609. At block 604, the processor engine calls the evaluation test component to determine whether the test operation evaluates to true or false. The called component sets the condition code flag to true or false. In decision block 605, if the condition code is true, the processor engine follows block 607, otherwise the processor engine follows block 606. At block 606, the processor engine adds a fake branch field offset to the current instruction pointer, then loops into block 601 to fetch the next instruction. Is the processor engine a true branch in block 607? Adds the offset of this field to the current instruction pointer, then loops into block 601 and fetches the next instruction. At block 608, the processor engine calls the non-test execution component, then loops into block 601 to fetch the next instruction. The non-test execution component performs an instruction operation and sets the current instruction pointer to point to the next instruction to be executed. The non-test execution component adds a true branching offset of the instruction (or parameter 2 for jump instructions) to the instruction pointer. At block 609, the component executes a stop instruction and then completes.
FIG. 7 is a flow chart illustrating the processing of the indirect reference component of the security virtual machine of one embodiment. This component dereferences parameter 1 and parameter 2 of the fetched instruction. In blocks 701-708, the component dereferences parameter 1. In decision block 701, if parameter 1 is the system call parameter indicated by the parameter 1 descriptor, the component follows block 703, otherwise the component follows block 702. At block 702, the component sets the dereferenced parameter 1 to the process control information specified by the index of parameter 1 and then follows block 709. In decision block 703, if the index of parameter 1 indicates that the system call parameter is an integer, the component follows block 704, otherwise the component follows block 705. At block 704, the component sets the dereferenced parameter 1 to the integer specified by the index, following block 709. In decision block 705, if the index of parameter 1 indicates that the system call parameter is a string, the component follows block 706, otherwise the component follows block 707. At block 706, the component sets the dereferenced parameter 1 to the string specified by the index, following block 709. In decision block 707, if the index of parameter 1 indicates that the system call parameter is low binary, the component follows block 708, otherwise an error has occurred. At block 708, the component sets the dereferenced parameter 1 to the raw binary specified by the index, following block 709. In blocks 709-714, the component dereferences parameter 2. Judgment block 709, para If the meter 2 descriptor points to immediate data, the component follows block 710, otherwise the component follows block 711. At block 710, the component sets the dereferenced parameter 2 to the value of parameter 2 in the fetched instruction and then returns. In decision block 711, if the parameter 2 descriptor points to literal data, the component follows block 712, otherwise the component follows block 713. At block 712, the component sets the dereferenced parameter 2 to the literal data specified by parameter 2 in the fetched instruction and then returns. In decision block 713, if the parameter 2 descriptor points to dynamic data, the component follows block 714, otherwise an error has occurred. At block 714, the component sets the dereferenced parameter 2 to the dynamic data specified by parameter 2 in the fetched instruction and then returns.
FIG. 8 is a flow chart illustrating the processing of the evaluation test component of the security virtual machine of one embodiment. The component decodes the operation code of the loaded instruction and calls the component to test the operation code. The called component sets the condition code to true or false. In decision blocks 801 to 803, the component decodes the operation code of the loaded instruction. In blocks 804-806, the component calls the component to implement the decoded operation code and then returns.
FIG. 9 is a flow chart illustrating the processing of the test component of the security virtual machine of one embodiment. The test component implements the test operation code. At block 901, the component sets the condition code to the value of the dereferenced parameter 2 and then returns.
FIG. 10 is a flow chart illustrating the processing of the character string matching component of the security virtual machine of one embodiment. The component determines if the dereferenced parameter 1 matches the dereferenced parameter 2. In one embodiment, the security virtual machine can use pattern matching. For example, the parameter can contain a "wildcard" designation or, more generally, a regular expression. In decision block 1001, if the lengths of parameter 1 and parameter 2 match, the component follows block 1003, otherwise these dedirected parameters cannot match and the component follows block 1002. .. At block 1002, the component sets the condition code to false and then returns. In blocks 1003-1006, the component loops while checking each character in the string of these dereferenced parameters. At block 1003, the component selects the next character in each string. In decision block 1004, if all characters in the string are already selected, the component follows block 1008, otherwise the component follows block 1005. At block 1005, the component normalizes the selected character. For example, a component can perform a case insensitive comparison with each letter in lowercase. In decision block 1006, if the selected characters match, the component loops into block 1003 and selects the next character in the string, otherwise the component continues to block 1007. At block 1007, the component sets the condition code (also called cc) to false and then returns. At block 1008, all characters in the string match, the component truly sets the condition code, and then returns.
FIG. 11 is a flow chart illustrating the processing of the non-test component of the security virtual machine of one embodiment. The component performs an operation on the untested operation code of the fetched instruction, including setting the current instruction pointer to point to the next instruction to execute. In decision block 1101, if the operation code is an action operation, the component follows block 1102, otherwise the component follows block 1103. At block 1102, the component adds parameter 2 of the fetched instruction to the action output set, and then follows block 1107. In decision block 1103, if the operation code is a reset operation, the component follows block 1104, otherwise the component follows block 1105. At block 1104, the component clears the action output set and then continues to block 1107. In decision block 1105, if the operation code is a jump operation, the component follows 1106, otherwise the component continues to decode further operation code. At block 1106, the component adds parameter 2 to the current instruction pointer and then returns. At block 1107, the component adds the value of the true branch field (also called tb) to the current instruction pointer and then returns.
Although specific embodiments of the security system have been described herein for illustration purposes, it will be appreciated by those skilled in the art that various modifications can be made without departing from the spirit and scope of the invention. It will be appreciated by those skilled in the art that security systems that use security virtual machines can be used to enforce a wide variety of security policies. For example, a security system can be used to secure messages received over a network, transactions received by a transaction processor, and more generally any application that provides an application programming interface. Therefore, the present invention is not limited to the scope of the appended claims.
<figref num="1">It is a block diagram which illustrates the component of the security system of one Embodiment.</figref><figref num="2">It is a block diagram which illustrates the data structure of the data store of one Embodiment.</figref><figref num="3">It is a figure which illustrates the layout of the instruction of the security virtual machine of one embodiment.</figref><figref num="4">It is a flow diagram which illustrates the processing of the program load component of one Embodiment.</figref><figref num="5">It is a flow diagram which illustrates the processing of the system call intercept component of one Embodiment.</figref><figref num="6">It is a flow diagram which illustrates the processing of the processor engine of the security virtual machine of one Embodiment.</figref><figref num="7">It is a flow diagram which illustrates the processing of the indirect reference component of the security virtual machine of one Embodiment.</figref><figref num="8">It is a flow chart which illustrates the process of the evaluation test component of the security virtual machine of one Embodiment.</figref><figref num="9">It is a flow diagram which illustrates the processing of the test component of the security virtual machine of one Embodiment.</figref><figref num="10">It is a flow diagram which illustrates the processing of the character string match component of the security virtual machine of one Embodiment.</figref><figref num="11">It is a flow diagram which illustrates the processing of the non-test component of the security virtual machine of one Embodiment.</figref>
Code description
100 user mode 101 application 102 Policy compiler 103 Policy Store 110 security system 120 kernel mode 121 System call intercept 122 Program load 127 processor engine 128 instruction store 129 data store 202 Literal data table 203 Literal data store 211 Dynamic data table 221 system call parameters 222 string table 223 Integer table 224 low binary table 231 Process control block table 241 Action output set
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| JP2004126854A | Cites | Japan |
| WO03104981A2 | Cites | World Intellectual Property Organization (WIPO) |
| JP2003173301A | Cites | Japan |
| JP2005529401A | Cites | Japan |
| WO03050662A1 | Cites | World Intellectual Property Organization (WIPO) |
| JP2000083049A | Cites | Japan |
28 members in 17 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 10832798 | United States of America | – | |
| 83279804 | United States of America | A | |
| 83279804 | United States of America | A | |
| 2004832798 | – | – | – |
| US20040832798 | – | – | – |
Members28
| Document | Office | Kind | |
|---|---|---|---|
| NO20051525D0 | Norway | D0 | |
| CA2499688A1 | Canada | A1 | |
| NO20051525L | Norway | L | |
| MXPA05003403A | Mexico | A | |
| CN1690957A | China | A | |
| JP2005316964A | Japan | A | |
| EP1596298A1 | European Patent Office (EPO) | A1 | |
| US2005257243A1 | United States of America | A1 | |
| SG116580A1 | Singapore | A1 | |
| BRPI0501171A | Brazil | A | |
| KR20060044764A | Republic of Korea | A | |
| TW200617702A | Taiwan Province of China | A | |
| RU2005107408A | Russian Federation | A | |
| CO5680123A1 | Colombia | A1 | |
| ZA200502451B | South Africa | B | |
| AU2005200911A1 | Australia | A1 | |
| NZ539022A | New Zealand | A | |
| RU2390837C2 | Russian Federation | C2 | |
| CN1690957B | China | B | |
| AU2005200911B2 | Australia | B2 | |
| JP4902129B2This record | Japan | B2 | |
| KR101143154B1 | Republic of Korea | B1 | |
| MY147383A | Malaysia | A | |
| US8607299B2 | United States of America | B2 | |
| TWI423040B | Taiwan Province of China | B | |
| CA2499688C | Canada | C | |
| NO336813B1 | Norway | B1 | |
| EP1596298B1 | European Patent Office (EPO) | B1 |
25 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313113S111 | S111 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 4902129
- Publication, DOCDB
- 4902129
- Publication, EPODOC
- JP4902129B
- Application
- 88743
- Application, DOCDB
- 2005088743
- Application, EPODOC
- JP20050088743
Titles2
- English
- Security Methods and systems for enforcing security policies through virtual machines
- Japanese
- セキュリティ仮想マシンを介してセキュリティポリシーを実施するための方法およびシステム
Classification
- CPC, 3
- G06F21/554
- E01H5/066
- G06F21/6218
- IPC, 3
- G06F21 00
- G06F21 56
- G06F9 455