IP Library Granted Patent US 8,132,164
Granted Patent B1
US 8,132,164 · App. 11/194,300 · Granted Mar 6, 2012

System, method and computer program product for virtual patching

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,132,164
App. No.
11/194,300
Granted
Mar 6, 2012
Kind
B1
Abstract

A system, method, and computer program product are provided for virtual patching. Initially, information associated with at least one vulnerability of a computer application is collected. Further, at least one host interface is identified that is capable of being used to access the vulnerability. In use, data sent to the at least one host interface is analyzed to determine whether the data is unwanted, based on the information.

Claims (39)

1. A method to be performed in conjunction with a processor configured for executing non-transitory instructions stored in a memory, the method comprising:

collecting information associated with at least one vulnerability of a computer application;

identifying at least one host interface that is capable of being used to access the vulnerability of the computer application;

analyzing data sent to the at least one host interface that was identified to determine whether the data is unwanted, wherein the identifying includes reproducing the vulnerability of the computer application, and determining a root cause of the vulnerability of the computer application, wherein a vector that is associated with the root cause is recorded, and wherein the vector is provided in a same form as an object in which the vulnerability is located; and

creating a detection algorithm, which is based on the root cause, to be used in detecting subsequent unwanted data instances.

2. The method of claim 1 , wherein the information is collected from a software patch.

3. The method of claim 1 , further comprising initiating an event if the data is determined to be unwanted.

4. The method of claim 3 , wherein the event includes preventing the data from accessing the at least one host interface that was identified.

5. The method of claim 3 , wherein the event includes creating a software exception.

6. The method of claim 3 wherein the event includes suspending a thread executing the data.

7. The method of claim 3 , wherein the event includes terminating execution of a process associated with the data.

8. The method of claim 1 , wherein the information includes public information.

9. The method of claim 1 , wherein the information is collected utilizing black box testing.

10. The method of claim 1 , wherein the information is collected utilizing binary differentiation.

11. The method of claim 1 , wherein the at least one host interface is identified utilizing a debugger.

12. The method of claim 1 , wherein the at least one host interface is identified utilizing a static analysis.

13. The method of claim 1 , wherein a closest host interface is identified and only data sent to the closest host interface is analyzed, when a plurality of the host interfaces is identified.

14. The method of claim 1 , wherein the collecting, identifying and analyzing are capable of being disabled.

15. The method of claim 1 , wherein the collecting includes:

filtering the information; and

classifying the information.

16. The method of claim 15 , wherein the filtering includes identifying at least one of a vulnerability name, a severity level, and an affected platform.

17. The method of claim 1 , wherein the at least one host interface includes a function that serves as an access point to the vulnerability of the computer application.

18. The method of claim 1 , further comprising intercepting all calls attempting to access the at least one host interface, and validating each call before allowing the call to proceed via the at least one host interface.

19. A computer program product embodied on a non-transitory computer readable medium for performing operations, the operations comprising:

collecting information associated with at least one vulnerability of a computer application;

identifying at least one host interface that is capable of being used to access the vulnerability of the computer application, utilizing a processor; and

analyzing data sent to the at least one host interface that was identified to determine whether the data is unwanted, wherein the identifying includes reproducing the vulnerability of the computer application, and determining a root cause of the vulnerability of the computer application, wherein a vector that is associated with the root cause is recorded, and wherein the vector is provided in a same form as an object in which the vulnerability is located; and

creating a detection algorithm, which is based on the root cause, to be used in detecting subsequent unwanted data instances.

20. A system, comprising:

a processor configured for executing non-transitory instructions stored in a memory, wherein the system is configured for:

collecting information associated with at least one vulnerability of a computer application;

identifying at least one host interface that is capable of being used to access the vulnerability of the computer application, wherein the system is operable such that data sent to the at least one host interface that was identified is analyzed to determine whether the data is unwanted, wherein the system is operable such that the identifying includes reproducing the vulnerability of the computer application, and determining a root cause of the vulnerability of the computer application, wherein a vector that is associated with the root cause is recorded, and wherein the vector is provided in a same form as an object in which the vulnerability is located; and

creating a detection algorithm, which is based on the root cause, to be used in detecting subsequent unwanted data instances.

21. A method to be performed in conjunction with a processor configured for executing non-transitory instructions stored in a memory, the method comprising:

collecting information associated with at least one vulnerability of a computer application, including filtering the information and classifying the information;

identifying at least one host interface that is capable of being used to access the vulnerability of the computer application, utilizing a processor, the vulnerability of the computer application being reproduced and a root cause analysis being performed to identify the at least one host interface, wherein a vector that is associated with the root cause is recorded, and wherein the vector is provided in a same form as an object in which the vulnerability is located;

analyzing data sent to the at least one host interface that was identified to determine whether the data is unwanted, based on the information; and

creating a detection algorithm, which is based on the root cause, to be used in detecting subsequent unwanted data instances.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2005
From: HOROVITZ, ODED; HOLLANDER, YONA
To: MCAFEE, INC.
Reel/Frame 016833/0592 →