FIELD: physics, computer engineering.
SUBSTANCE: invention refers to the field of computer security. The method is proposed, including hypervisor code loading to the random-access memory prior to operating system booting; a trusted module to call the hypervisor code execution is loaded to RAM during operating system booting; the first request to the hypervisor from the trusted module in order to obtain the hypervisor address in RAM is sent; a cryptographic key is generated using the hypervisor; the specified key is saved in the hypervisor memory; a memory page is allocated; the specified key and hypervisor address in RAM are recorded in the selected memory page; protection for the allocated memory page is set; a request to the hypervisor at the address recorded in the page selected in step g) is sent from the trusted module in order to call hypervisor code execution, at that, the request contains the key, recorded in the allocated page; the key is checked by means of the hypervisor by comparing the key transmitted in the request sent to the hypervisor from the trusted module to the key stored in the hypervisor memory; if the result is positive, the code is executed in the hypervisor mode.
EFFECT: code execution is provided in the hypervisor mode.
5 dwg
Title | Year | Author | Number |
---|---|---|---|
METHOD OF CREATING ANTIVIRUS RECORD WHEN DETECTING MALICIOUS CODE IN RANDOM-ACCESS MEMORY | 2015 |
|
RU2592383C1 |
METHOD OF DETECTING MALICIOUS CODE IN RANDOM-ACCESS MEMORY | 2015 |
|
RU2589862C1 |
SYSTEM AND METHOD OF GENERATING LOG WHEN EXECUTING FILE WITH VULNERABILITIES IN VIRTUAL MACHINE | 2018 |
|
RU2724790C1 |
SYSTEM AND METHOD FOR LOG FORMING IN VIRTUAL MACHINE FOR ANTI-VIRUS FILE CHECKING | 2017 |
|
RU2649794C1 |
METHOD OF INVOKING SYSTEM FUNCTIONS IN CONDITIONS OF USE OF AGENTS FOR PROTECTING OPERATING SYSTEM KERNEL | 2014 |
|
RU2585978C2 |
ATTESTATION OF HOST CONTAINING TRUSTED EXECUTION ENVIRONMENT | 2015 |
|
RU2679721C2 |
METHOD OF CREATING A SYSTEM CALL HANDLER | 2014 |
|
RU2596577C2 |
SECURITY AGENTS AND PRIVILEGED MODES | 2007 |
|
RU2468418C2 |
SYSTEM AND METHOD OF DETECTING MALICIOUS SCRIPT | 2017 |
|
RU2659738C1 |
SYSTEM AND METHOD OF DETECTING THE HARMFUL CODE IN THE ADDRESS PROCESS SPACE | 2017 |
|
RU2665910C1 |
Authors
Dates
2017-02-02—Published
2015-09-30—Filed