1. A clamping device for selectively maintaining a position of a first workpiece and a second workpiece, the clamping device comprising:
an electrostatic clamping plate annulus generally surrounding a central portion, wherein the electrostatic clamping plate annulus comprises a clamping surface and has a diameter associated with a diameter of the first workpiece, wherein the diameter of the first workpiece is larger than a diameter of the second workpiece, and wherein the electrostatic clamping plate annulus is configured to selectively electrostatically clamp a circumferential portion of the first workpiece to the clamping surface thereof;
a non-electrostatic central portion comprising a heater, wherein the central portion has a diameter associated with the diameter of the second workpiece; and
a workpiece carrier, wherein the workpiece carrier is configured to substantially hold the second workpiece, and wherein a diameter of the workpiece carrier is associated with the diameter of the electrostatic clamping plate annulus, and wherein the electrostatic clamping plate annulus is further configured to selectively clamp the workpiece carrier to the clamping surface thereof, therein selectively maintaining a position of the second workpiece with respect to the non-electrostatic central portion.
2. The clamping device of claim 1, wherein the electrostatic clamping plate annulus comprises one or more electrodes associated with the circumferential portion of the first workpiece, wherein a voltage applied to the one or more electrodes is operable to selectively electrostatically attract the at least the first workpiece to the clamping surface.
3. The clamping device of claim 2, wherein a voltage applied to the one or more electrodes is operable to selectively electrostatically attract the workpiece carrier to the clamping surface.
4. The clamping device of claim 1, further comprising one or more auxiliary clamping members configured to selectively secure at least a portion of one or more of the first workpiece and the workpiece carrier to the clamping surface.
5. The clamping device of claim 1, wherein one or more of the first workpiece and second workpiece comprises one or more of silicon, silicon carbide, germanium, and gallium arsenide.
6. The clamping device of claim 1, wherein the workpiece carrier comprises one or more of aluminum oxide, silicon carbide, silicon dioxide.
7. The clamping device of claim 1, wherein the heater comprises one or more of heat lamps and resistance heaters associated with the non-electrostatic central portion.
8. The clamping device of claim 1, wherein the heater is positioned below a plane of at least the second workpiece when the second workpiece is held in the workpiece carrier.
9. The clamping device of claim 1, further comprising a shield positioned between the non-electrostatic central portion and the electrostatic clamping plate annulus, wherein the shield generally provides a thermal barrier between the non-electrostatic central portion and the electrostatic clamping plate annulus.
10. The clamping device of claim 1, wherein the workpiece carrier further comprises one or more retention devices configured to selectively restrain the second workpiece therein.
11. The clamping device of claim 1, wherein the workpiece carrier comprises one or more of a flat and a pin configured to selectively retain the second workpiece in a fixed rotational position with respect to the workpiece carrier.
12. The clamping device of claim 1, wherein one or more of the first workpiece and second workpiece comprises one or more of silicon, silicon carbide, germanium, and gallium arsenide.
13. The clamping device of claim 1, wherein the electrostatic clamping plate annulus is further configured to selectively electrostatically clamp the workpiece carrier to the clamping surface thereof, therein selectively maintaining a position of the second workpiece with respect to the non-electrostatic central portion.
14. A method clamping workpieces of varying sizes, the method comprising:
providing a first workpiece of a first size and a second workpiece of a second size, wherein the first size is greater than the second size;
providing a workpiece carrier having a third size approximating the first size, and wherein the workpiece carrier is configured to selectively retain the second workpiece therein;
placing the second workpiece in the workpiece carrier;
placing one of the first workpiece and workpiece carrier on a clamping surface of a clamping device, the clamping device comprising an electrostatic clamp annulus generally surrounds a non-electrostatic central portion; and
selectively providing a clamping force to the electrostatic clamp annulus, therein selectively clamping the respective first workpiece and workpiece carrier to the clamping surface.
15. The method of claim 14, further comprising heating the central portion of the clamping device when the workpiece carrier holding the second workpiece is clamped to the clamping surface.
16. The method of claim 15, wherein heating the central portion comprises energizing one or more of a heat lamp assembly and a resistive heater assembly associated with the second workpiece.
17. The method of claim 14, further comprising cooling the electrostatic clamp annulus when the first workpiece is clamped to the clamping surface.
18. The method of claim 14, further comprising selectively applying an auxiliary mechanical clamping force to one or more of the first workpiece, second workpiece, and workpiece carrier, based on one or more predetermined conditions.
19. The method of claim 18, wherein the one or more predetermined conditions comprise a predetermined temperature of one or more of the first and second workpiece and the electrostatic chuck.
20. The method of claim 14, wherein selectively providing a clamping force to the electrostatic clamp comprises selectively providing a clamping voltage to the electrostatic clamp annulus, therein selectively electrostatically clamping the respective first workpiece and workpiece carrier to the clamping surface.
The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.
1. In a computer that comprises
an operating system, a method of identifying a program configured to conceal malware installed on the computer, the method comprising:
employing kernel debugger facilities to obtain data maintained by the operating system by causing the kernel debugger facilities to set a break point when a suspicious activity inclusive of a characteristic of a RootKit is identified; and
checking the data, representing contents of a data structure when the breakpoint was set, and obtained by the kernel debugger facilities, for inconsistencies that are characteristic of a program that conceals malware,
wherein the computer includes a computer-readable storage medium comprising the kernel debugger facilities executable by the computer.
2. The method as recited in claim 1, wherein the kernel debugger facilities are exposed to other software modules on the computer as a set of library routines.
3. The method as recited in claim 2, wherein checking the data obtained by the kernel debugger facilities for inconsistencies that are characteristic of a program that conceals malware is performed in an extension to the kernel debugger facilities.
4. The method as recited in claim 1, wherein the kernel debugger facilities are located on a device that maintains a direct connection with the computer; and
wherein data requested by the kernel debugger facilities is transmitted to the device that maintains the direct connection using an interface for communicating over the direct connection.
5. The method as recited in claim 1, wherein the kernel debugger facilities are located on a remote computer; and
wherein data requested by the kernel debugger facilities is transmitted to the remote computer over a network connection.
6. The method as recited in claim 5, wherein checking the data obtained by the kernel debugger facilities for inconsistencies that are characteristic of a program that conceals malware is performed on a remote computer as a Web service.
7. The method as recited in claim 1, wherein checking the data obtained by the kernel debugger facilities for inconsistencies that are characteristic of a program that conceals malware is performed in a driver that may be accessed by a user-mode application program.
8. The method as recited in claim 1, wherein checking the data obtained by the kernel debugger facilities for inconsistencies that are characteristic of a program that conceals malware comprises:
using a hash function to generate a signature from the data obtained by the kernel debugger facilities that identifies the state of the computer;
comparing the signature to a signature generated from a computer that is infected with a RootKit; and
comparing the signature to a signature generated from a computer that contains a benevolent program that intercepts communications made to the operating system.
9. The method as recited in claim 1, wherein checking the data obtained by the kernel debugger facilities for inconsistencies that are characteristic of a program that conceals malware comprises using heuristics to quantify characteristics that are associated with RootKit by setting a breakpoint when a modification is made to a process table.
10. A computer-readable medium bearing computer-executable instructions that, when executed on a computer that comprises
an operating system, causes the computer to:
set a breakpoint when a suspicious activity inclusive of a characteristic of a RootKit is identified;
in response to the occurrence of a scan event, employ kernel debugger facilities to obtain data maintained by the operating system when the breakpoint was set; and
determine whether the data obtained by the kernel debugger facilities contains inconsistencies that are characteristic of a RootKit;
wherein the computer-readable medium comprises a computer-readable storage medium comprising the kernel debugger facilities.
11. The computer-readable medium as recited in claim 10, wherein if inconsistencies that are characteristic of a RootKit are identified, the computer-readable medium is further configured to cause the computer to remove the RootKit from the computer.
12. The computer-readable medium as recited in claim 11, wherein removing the RootKit from the computer comprises:
terminating a process associated with the RootKit,
removing RootKit generated entries from configuration files; and
deleting a file that contains program code that implements the RootKit.
13. In a computer that comprises an operating system, a software system for identifying a program designed to conceal malware installed on a computer, the software system comprising:
kernel debugger facilities operative to obtain data in data structures maintained by the operating system by setting a break point when a suspicious activity inclusive of a characteristic of a RootKit is identified;
an integrity checker for determining whether data obtained by the kernel debugger facilities when the breakpoint was set contains inconsistencies characteristic of the RootKit;
a detection module that coordinates obtaining data maintained by the operating system and providing the data to the integrity checker; and
a computer-readable storage medium comprising the kernel debugger facilities, integrity checker and detection module executable by a computer.
14. The software system as recited in claim 13, further comprising an interface for communicating with application programs installed on the computer; and
wherein the integrity checker determines whether data obtained by the kernel debugger facilities contains inconsistencies characteristic of a RootKit by comparing data reported by the interface with data obtained by the kernel debugger facilities.
15. The software system as recited in claim 13, wherein the detection module is contained in a driver and the functionality of the detection module is exposed to a user mode application program.
16. The software system as recited in claim 13, wherein the detection module is further configured to generate a unique signature from data in memory of the computer for comparison to signatures generated from a known Rootkit.
17. The software system as recited in claim 16, wherein the detection module is further configured to compare the signature of the data obtained by the kernel debugger facilities to a signature generated from a computer infected with a RootKit.
18. The software system as recited in claim 13, wherein the integrity checker uses heuristics in determining whether data obtained by the kernel debugger facilities contains inconsistencies characteristic of a RootKit by setting a breakpoint when a modification is made to a process table.
19. The software system as recited in claim 14, wherein the integrity checker checks references to memory addresses that are outside of a normal range in determining whether data obtained by the kernel debugger facilities contains inconsistencies characteristic of a RootKit.