Rootkit detection system and method

Number of patents in Portfolio can not be more than 2000

United States of America Patent

APP PUB NO 20080016571A1
SERIAL NO

11485036

Stats

ATTORNEY / AGENT: (SPONSORED)

Importance

Loading Importance Indicators... loading....

Abstract

See full text

A system and method is provided for detecting operating system compromises due to inconspicuous rootkit installations. A rootkit detection module identifies hidden processes running on top of the operating system. Processes operating in an uncompromised environment expose their process identifiers (PIDs) to the operating system. Thus, if a hidden process is discovered, this is an indication that a rootkit program may have compromised the operating system. The rootkit detection mechanism according embodiments of the present invention detect hidden processes by identifying a range of all possible PIDs and identifying PIDs that are not being reported by the operating system. Specifically, the rootkit detection mechanism according to one embodiment of the invention tests each PID in the range via lower level function calls that do not rely on published operating system APIs, and examines the memory location referenced by the PID for determining if a hidden process exists.

Loading the Abstract Image... loading....

First Claim

See full text

Family

Loading Family data... loading....

Patent Owner(s)

Patent OwnerAddress
GUIDANCE SOFTWARE INC1055 E COLORADO BLVD PASADENA CA 91106-2375

International Classification(s)

Inventor(s)

Inventor Name Address # of filed Patents Total Citations
Chang, Larry Chung Yao Walnut, CA 2 15

Cited Art Landscape

Load Citation

Patent Citation Ranking

Forward Cite Landscape

Load Citation