METHOD OF CREATING A SYSTEM CALL HANDLER Russian patent published in 2016 - IPC G06F21/00 

Abstract RU 2596577 C2

FIELD: information technology.

SUBSTANCE: invention relates to antivirus technologies, particularly to a method of creating handler system calls. Way to contact modified system call handler of system calls in Windows operating system consists of steps where: localized code of original handler system calls; modified system call handler is created by memory allocation and copying code to original handler additionally, the next step is performed: changing the address of the original handler on the address of the modified handler; intercepted call processor instructions associated with a system call, using a hypervisor; saved value register MSR using a hypervisor for its return process Patch Guard when reading the last value of register MSR for correct work of the operating system; one contacts a modified system call for interception operations associated with removal of images of the screen.

EFFECT: technical result of this invention is providing the possibility of processing system calls.

1 cl, 7 dwg

Similar patents RU2596577C2

Title Year Author Number
METHOD OF INVOKING SYSTEM FUNCTIONS IN CONDITIONS OF USE OF AGENTS FOR PROTECTING OPERATING SYSTEM KERNEL 2014
  • Yudin Maksim Vitalevich
  • Tarasenko Aleksandr Sergeevich
  • Levchenko Vyacheslav Ivanovich
  • Kumagin Igor Yurevich
RU2585978C2
METHOD OF ACCESSING PROCEDURES OF LOADING DRIVER 2014
  • Rusakov Vyacheslav Evgenevich
  • Kirzhemanov Andrej Leonidovich
  • Parshin Yurij Gennadevich
RU2586576C1
MEMORY INTROSPECTION ENGINE FOR PROTECTING INTEGRITY OF VIRTUAL MACHINES 2014
  • Lutsas Andrej-Vlad
  • Lukaks Sandor
  • Lutsas Dan-Khorya
RU2640300C2
METHOD OF PROVIDING COLLABORATIVE OPERATION OF SEVERAL HYPERVISORS IN COMPUTER SYSTEM 2014
  • Levchenko Vyacheslav Ivanovich
  • Kumagin Igor Yurevich
RU2589853C1
METHOD FOR CODE PERFORMANCE IN HYPERVISOR MODE 2015
  • Igotti Nikolaj Nikolaevich
  • Ershov Mikhail Aleksandrovich
RU2609761C1
SYSTEM AND METHODS FOR AUDITING A VIRTUAL MACHINE 2017
  • Lukacs Sandor
  • Lutas Andrei-Vlad
  • Anichitei Ionel C.
RU2691187C1
SYSTEM AND METHOD OF DETECTING MALICIOUS CODE IN FILE 2016
  • Golovkin Maksim Yurevich
  • Monastyrskij Aleksej Vladimirovich
  • Pintijskij Vladislav Valerevich
  • Pavlyushchik Mikhail Aleksandrovich
  • Butuzov Vitalij Vladimirovich
  • Karasovskij Dmitrij Valerievich
RU2637997C1
SYSTEM AND METHOD OF PROTECTING COMPUTER APPLICATIONS 2011
  • Rusakov Vjacheslav Evgen'Evich
  • Shirjaev Aleksandr Vasil'Evich
RU2460133C1
METHOD OF RECALL OF ORIGINAL FUNCTION AFTER ITS INTERCEPTION WITH SAVING OF STACK OF PARAMETERS 2013
  • Ledenev Aleksandr Vjacheslavovich
RU2546588C2
SYSTEM AND METHOD FOR PERFORMING ANTI-VIRUS SCAN OF FILE ON VIRTUAL MACHINE 2016
  • Monastyrskij Aleksej Vladimirovich
  • Butuzov Vitalij Vladimirovich
  • Golovkin Maksim Yurevich
  • Karasovskij Dmitrij Valerievich
  • Pintijskij Vladislav Valerevich
  • Kobychev Denis Yurevich
RU2628921C1

RU 2 596 577 C2

Authors

Yudin Maksim Vitalevich

Tarasenko Aleksandr Sergeevich

Levchenko Vyacheslav Ivanovich

Kumagin Igor Yurevich

Dates

2016-09-10Published

2014-09-30Filed