METHOD AND APPARATUS TO DETECT KERNEL MODE ROOTKIT EVENTS THROUGH VIRTUALIZATION TRAPS
Patent №
US 7,845,009
Granted
2010-11-30
Filed 2006
Owner
INTEL CORPORATION
Lab
—
AI components
1
planning
Assignment
Recorded
Dataset
AIPD
2023_r1 edition
Application
11435463
Detecting a rootkit in a computing system may be achieved by detecting, by a virtual machine monitor, a virtualization trap occurring as a result of an action by a rootkit executing in a computing system; and analyzing the virtualization trap to detect the presence of the rootkit in the computing system. Action may then be taken to block the rootkit activity to safeguard the computing system.
AI classification
Ownership
INTEL CORPORATION
assignment · 201810001
Assignors
GROBMAN, STEVEN
On an employer assignment, the assignors are typically the inventors.