The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Nov. 24, 2015

Filed:

Jan. 28, 2015
Applicant:

Kaspersky Lab Zao, Moscow, RU;

Inventors:

Vyacheslav E. Rusakov, Moscow, RU;

Andrey L. Kirzhemanov, Moscow, RU;

Yury G. Parshin, Moscow, RU;

Assignee:
Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/57 (2013.01); G06F 21/56 (2013.01);
U.S. Cl.
CPC ...
G06F 21/575 (2013.01); G06F 21/561 (2013.01); G06F 21/568 (2013.01);
Abstract

Disclosed are systems and methods for detecting access of boot driver routines by malware. An example method includes identifying, by the driver interceptor, the one or more boot drivers that have been loaded into memory but not yet initialized; installing, by the driver interceptor, an interceptor handler operable to intercept calls of initialization routines of the one or more identified boot drivers; intercepting, by the driver interceptor, program calls to the initialization routines of the one or more identified boot drivers; storing, by intercept handler, information about the boot driver that is provided by the driver in the course of its initialization, wherein information contains at least address of the entry point for one or more routines of the boot driver; and providing access, by driver interceptor, to the routines of the boot driver by previously stored addresses of the entry points.


Find Patent Forward Citations

Loading…