(19) PEAR MEA RAR ze
+p (12) RERSAl *
: Cop eRARAHS CN 108055138
(45) RAHA 2016. 11. 23
(21) HHS 201410215459.3 (56) wie StF
(22) #848 2014.05.21 CN 101226577 A,2008.07.23,
CN 102096786 A,2011.06.15,
(SS) IRE ARS Xiaoxin Chen*.Overshadow: a
RBIRAAGS ON 103955438 A virtualization-based approach to
(43) RBA 2014.07.30 retrofitting protection in commodity
(73) SHILA, operating systems. (ACM SIGOPS Operating
Shit 210093 ELI ade Systems Review).2008, 342% 520)), 250.
. Hai Jin.Cherub: Pine-grained
(ARMA Ri Ate application protection with on-demand
(74) SFO HRC eA bo CHRAIR = virtualization. Fie HHH AL VMNONSES Hil
[0029] VMXON- #4 3K CPU SE He SOLA AS PT LF A » ede PO A
SEA YS ABR) EE IOLA SCF PAS 15, AAG AL HL HDS AE AF
TA32_VMX_BASI CIA AACS {5 BAAR «
(looso] 2) FF AVM BE TE BES
Coos] VIER ARH SLAY PUA BERL: HE BERL (Root) AIAE HE BEE (Non-Root) » HE PUEVMM EE A
PEAT PERE, TA POLAR AE EIS AT TAR AES BE Fy VN BR EAE
SeLGA I VMNONSS OF AAT T VMN BRE BESK Zs CPUBDI FFP MEHL A VM] LAGE VMENTRY
BEA BI PPLE RSE PT 5 Ee POLE SEIS AT FAP BEL PE PLE
BRIEAT IN 23D AAT BURA SRD 7° VMEXT TBs A SURES BU ARM ig BH
VOXASESE 5 AY DISH HY VMNOPP RTA ADL HE
[0032] 3 aPC RFE VCS HHI
(o0as] VCS 4a A SHS VMI PLAY BE AE 2 HE VICAR as, VM BR
THAR BS ALVIS AB DK 3-4 BE SS A 6 BP CSAS BX BE LG = BUR ARE VOR AS
ARAR RAE , VW-Executi ond 15K , VMENTRY4T 2943 #839 , VMEX 14 Aa $3 tt] 38-ANINMEX LTH
{5 Sh.
[0034] ZRF VMCSHEE fil RING JL BLL HE HAY VM-Execu tion Eiht GORI FE AF
FUSCA RE REI ENMEN TTB PE 5 DAHER AE ATS CRORE AE A PRE A AI FEY 0
(ooss] 4) i ERB
(loose) ZEVMX BES, Sak — 4b 3 BR AS) — AR ICS 2A DE» FE AAT 18 4
MCS 9 4H VCS. “4 HOIST T HEME CPU FFAS THRE AE HUIS AT 5 ft
JR SHIVMCSHSS SN VMPTRLD 2 a SAF Ay BA Sack Ut FVM AUCH & Hl TP a eM LIZ AT
VMLAUCHE & Je miLaat AS AE BEE. CPUE ASE RRSN Z Jes, HS Ah Ee AT EL AE
VMEXITP=4E 5CN 103955438 B hh A 45H
(0037) FAPSAR I Ae BRS s SE aE AEA iL FEV MCL Lis 245 1 St) 4 Bie AP LD Ae i oH
FE MSH ERIE EMER ARASH RUN BE PE aa a a
385 SRG i Sete A ELE AT EG DOE SE RP Pe
Coos] Far EAh Ny eB « RF OU Ae Hak FR Be MAE A SO FATE BRL 5 AS A
FIRE GEDA AT BW BE Ae 1 i Ul i A OY 6 EI AL TP A NER
FRB ALTARS TAS, FALL BRE RHE AN DRS» EF
SRA EF He AZ HK RB He
(loos) FUE Ae AL He BL BE Pe TE AL SAL Ze» HH BE Db TE BEE
52 OVER OU REIL SS A CROAE-FE A ENT OE AGES BU FR 5 HE HT
SAY REEF BE 2e 19 LL SRA 6 Be PLE eA LY Re, AL He AT EZ
BR ASL PERE UAE «PALIT ER Ze ES UF BB ETE
HSA EB SY A EEO AB Le PE TR FETE MEARE AR Te OLA ES» RS
LPS ETE OY SE MY PA, BRE AT PB, Me A A UF Reh EE eT
FR PME A PWR RAIL EF RA
(0040) A Ak OY Hy SERA SERRA TO REE DURE SCH — fh A A RSF OLR HEMT
ARCHIE FS Ts Be, a PERF RS AEDT A PRIS FT
SAG HE PU FRAN] gi AE TE RAY PEE RE OE BE
FGA PITAL Ze Tal SS SR AE SPE SE RAP ET A TET SRA Fe
TIPS oT SAE REF ER SE RAPA AP EOLA BBO i SS RP FH DHS UIE,
(ST FAFA Ag eA OD FS J a BU SERA RS EERE AT
eS SU I ALFA RH AL UR DB AC ENT EAL Rh OL RS
SZERAP A FER Ui eS BT YE «DRE LS Yea.
(0041) Fir SAR AY Aaa HE ARE A EP Re SL SO, BD ER
THA PNY LAE AS LS DAA Re PL I A TS A TE SL RIE PASE A a aL
Cy RET Ta SE RP EPRI FF Td.
[0042] ADEPCData Executive Protection dit 47 GaP 48 AA] UA RED AR AAT FE
SCAG Sa A BEB OD LD ASL LAS BL SAAT 5 MA AR EHS IG BI A AR,
DR IRE He AR ACHR AT EAN BS» DEP HE FAB AF A BE So SEY fA EE 32 hE PAE
(Physical Address Extension ,432HUSLd° JE M30 F Windows} ,DEPAYSEELREAL ATT
Inte 12 HEHJEDB(Executive Disabled Bit). 7E32{2PARBESNF . 174828 F707 MEHL
BE WBS AK s 2A 1 RA EY OPE AY HT El ok a S| ORE AY TL eae a] AL 2B aE SLE
DN) SR OLHUCHI A Pe BL PRR AAS
[0043] Ace BYLINE BSE RAP BFL PF Re RO SY DAT RE RR
SPSS BAS BHU LET AS FY BAT» WER RE A BA) SER SER A PAS PE P BU,
47 BUILT ALP ase At.
(ood) Fira APRS WI RRER S CRI AE TE Ae TE AO EAE 5
[0045] aij a CRSP bl AE AA ITT? A AY VMEX 1 Tt BEER VM_EXTT_REASON AES HH 58 ADS-B
Aa0x0000001C , HEH Hil 85-7 Bas A Hi lr] EAH Ae 47 4EEXIT_QUALIFICATIONGE IH & fF)
FBCN 103955438 B hh A
(loode] i RE BEB At ial CRORE TF APR ES Ae CPOE
[0047] 1 3A) FVM_EX1T_REASONAE #3 ¥y0x0000001C, AE WFE2, 7 SEH «
(lo048] 2) #€4REXIT_QUALIPICATIONIO—3 iz $k ARH fl EAE BW AAI Ra FA
PAP ACRS FES) 6
[0049] 3 )#f4EEXTT_QUALIFICATIONG#4—S{i GRAPE ER OF ARIE a 5 6 FE SB LR
PRE ISE AE 17-28 ALON HE.
[0050] 4) #f4HSEXTT_QUALIPICATION(Y 1 : 8402 , Wye 38 FLAS 4 28»
(0051) 5) FAINT S ACRE 7 A (19 (ALA Fy 5 RAPE PRIN A SAE 2 MUS SESE Oy
SEAR UREA BAF HL 2 A SE.
(00S 2) aah ish JGR HLA SE TS WAHL RAPE A) URS A EE TDR 22 HE HE
HDRES RIE
(0053) Fh APSE RAPE REAL PSC IIR BA BES Ah Pe HY
(0054) 1 DRE RAP AE ARAND A PRR Ze ESE FL PAY Re OATS,
AE ANE BL A PO TH 1 I WU AS DT
[0055] 2) CPUAK AL PURSUE ABA BORSTAL A MES HE
BRAIN PARR TR
[0056] 3 )4ECROE TE AR ASR UHH Se RA EL AN BEF
[0057] FE APSE ARAM AEA RR IR A BY AL Pe LH
(OOS) LSE RAP AE ARIA PA A BRU Ze hE NE TP PEAS Re OATS,
PANE DAL, BB POT TA 1 Yo AS AT
(0069) 2) 4 CPUBK AY BEAR ACHAEA SA FE PUBRSRIND FPA UIE AY RCIA RB AA
BUSI PB TR
[0060] 3 ASCRIBE AE ASE AH LSA REAT HPF AR
Cocet] fish bigs AUS I APE a FRE HIE A BUS ASS ACACIA i ll BS RA
ROA Fail
(02) res ARM AED Be BE J I A AT A I ER AT PB ae
DUR SERS, MURALS RA EAE ZEON MIE PIL ILE Te EER, TENE
PEI AG BUR F TAP UTA SAU ERE AR ASO, WE OSE SER 8 AS
A FRR PIES TOWLE LL AS AS RAP I UL 5 Re Py a I HE
OES OUD VEE TUS DA SR ae TU ft AE AS ASN EZ SE RN AF Ud AE SER
PRERLLAT IL BF PLR P I HE AR LEE RR AS AEE WU SP EE EEE HH
FURIE A AS He BE, TE A SEE WS BELG 52 RAEN OF
AEE MUS AYES WS We a tL Ha Ys YTSCN 103955438 B he Bt LAK
SRP HE BAER
ote e (}
| ERS |
SAP HRCN 103955438 B
ke A oH Mt A
24h
MaARooAR USHER
PRAGMA DEA
ae
| AEAPAVEURMEN A, FHA RMN R AE RRR |
———
:
RUMECTSEE
&
a
t, a 2, Wm SHAM AOCRI
— 2ERPER Renew IRA
a4 RISA
Seetts =f
2 _—Reonaaee,, 2 (Enaameg
Say pea aR men
BORA ROA a
MRARAR EF RR
10ke A oH Mt A
CN 103955438 B 3/4
SER Code View
COFF FBR Sait.
CORFARS
reloc
edata
data
text
IMAGE_SECTION_HEADER
IMAGE_SECTION_HEADER
IMAGE_SECTION_HEADER
shh
IMAGE_SECTION_HEADER
EERE
IMAGE_OPTIONAL_HEADER32
IMAGE_FILE_HEADER
“PE”, 0,0
DOS stub
DOS ‘MZ’ HEADER
=
HR (Section)
ft
BRR
(Section Table)
-
PE SCRA
Dos 4a
|CN 103955438 B ke A oH Mt A
VA
SPORE
BP an see
HEAR FERS eee
BPR CRI
PRR aa
Rt
RARE em
BEF CRB
4
a 30_29 M20 12 11 0
DirectoryPonter| Directory Tbe ona
4KB Page
Pu Bile Physical
Page Directory
Page Directory Page Table
a Directory Entry
Dir. Pointer
CR3