IP Library Granted Patent US 8,555,404
Granted Patent B1
US 8,555,404 · App. 11/437,317 · Granted Oct 8, 2013

Connectivity-based authorization

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,555,404
App. No.
11/437,317
Granted
Oct 8, 2013
Kind
B1
Abstract

Techniques which allow definition and enforcement of connectivity-based action and execution authorization policies. On a computer, an action or execution attempt is intercepted in real-time. The connectivity state of the computer, the subject process, the program file of the subject process, the attempted action and the object of the attempted action are determined. An authorization policy considering the connectivity state indicates whether the attempted action is authorized or not. In a tracking mode, the attempted action and its authorization are logged and the attempted action is allowed to proceed. In an enforcement mode, unauthorized attempts are blocked and logged, thereby enforcing the authorization policy.

Claims (55)

1. A method of authorizing a file system action on a computer, the method steps comprising:

intercepting a file system action attempt indicating an action by a process on an object;

determining an identifier for the process;

using the identifier to determine a program file representing instructions being executed by the process;

determining a network connectivity state of the computer, wherein at least one entry in an authorization policy designates an authorization of a particular action for the program file based on the network connectivity state and a type of action associated with the particular action, and wherein a network connectivity state parameter includes an attribute associated with whether the computer is connected to a wired network or a wireless network;

determining whether the action is authorized or not based on the authorization policy, wherein the authorization policy includes the network connectivity state parameter, a program file parameter, an object parameter, and an attempted action parameter;

allowing the action by the process to proceed when the action is authorized, as indicated by the authorization policy; and

responding when a determination is made that the action is not authorized, wherein said responding comprises a first mode and a second mode, when in the first mode the action is blocked and an alert is generated, the alert including the type of action and the network connectivity state at the time the action was attempted, and when in the second mode the action is allowed to proceed and an alert is generated.

2. A method as recited in claim 1 , wherein the determining further determines one or more attributes of the process or of the program file.

3. A method as recited in claim 1 , wherein the action indicates a read operation on the object.

4. A method as recited in claim 1 , wherein the action indicates a write, append or truncate operation on the object.

5. A method as recited in claim 1 , wherein the action indicates a delete, move or rename operation on the object.

6. A computer-implemented method for authorizing registry actions on a computer that includes a processor and a non-transitory computer readable medium, comprising:

intercepting a registry action attempt indicating an action by a process on a registry entry;

determining an identifier for the process;

using the identifier to determine a program file representing instructions being executed by the process;

determining a network connectivity state of a computer, wherein at least one entry in an authorization policy designates an authorization of a particular action for the program file based on the network connectivity state and a type of action associated with the particular action, and wherein a network connectivity state parameter includes an attribute associated with whether the computer is connected to a wired network or a wireless network;

determining whether the action is authorized or not based on the authorization policy, wherein the authorization policy includes the network connectivity state parameter, a program file parameter, an object parameter, and an attempted action parameter;

allowing the action by the process to proceed when the action is authorized, as indicated by the authorization policy; and

responding when a determination is made that the action is not authorized, wherein said responding comprises a first mode and a second mode, when in the first mode the action is blocked and an alert is generated, the alert including the type of action and the network connectivity state at the time the action was attempted, and when in the second mode the action is allowed to proceed and an alert is generated.

7. A method as recited in claim 6 , wherein the determining further determines one or more attributes of the processor of the program file.

8. A method as recited in claim 6 , wherein the action indicates a read, retrieve, write, create or delete operation on the registry entry.

9. A method for authorizing executions on a computer that includes a processor and a non-transitory computer readable medium, comprising:

intercepting an execution attempt indicating a process attempting to execute an executable file;

determining an identifier for the process;

using the identifier to determine a program file representing instructions being executed by the process;

determining a network connectivity state of the computer, wherein at least one entry in an authorization policy designates an authorization of a particular execution for the program file based on the network connectivity state and a type of execution associated with the particular execution, and wherein a network connectivity state parameter includes an attribute associated with whether the computer is connected to a wired network or a wireless network;

determining whether the execution is authorized or not based on the authorization policy, wherein the authorization policy includes the network connectivity state parameter, a program file parameter, an object parameter, and an attempted execution parameter;

allowing the execution to proceed when the execution is authorized, as indicated by the authorization policy; and

responding when a determination is made that the execution is not authorized, wherein said responding comprises a first mode and a second mode, when in the first mode the execution is blocked and an alert is generated, the alert including the type of action and the network connectivity state at the time the execution was attempted, and when in the second mode the execution is allowed to proceed and an alert is generated.

10. A method as recited in claim 9 , wherein the determining further determines one or more attributes of the process or of the program file.

11. At least one non-transitory computer readable medium having instructions stored thereon, the instructions when executed by a processor cause the processor to:

intercept a file system action attempt indicating an action by a process on an object;

determine an identifier for the process;

use the identifier to determine a program file representing instructions being executed by the process;

determine a network connectivity state of the computer, wherein at least one entry in an authorization policy designates an authorization of a particular action for the program file based on the network connectivity state and a type of action associated with the particular action, and wherein a network connectivity state parameter includes an attribute associated with whether the computer is connected to a wired network or a wireless network;

determine whether the action is authorized or not based on the authorization policy, wherein the authorization policy includes the network connectivity state parameter, a program file parameter, an object parameter, and an attempted action parameter;

allow the action by the process to proceed when the action is authorized, as indicated by the authorization policy; and

respond when a determination is made that the action is not authorized, wherein a response comprises one of a first mode and a second mode, when in the first mode the action is blocked and an alert is generated, the alert including the type of action and the network connectivity state at the time the action was attempted, and when in the second mode the action is allowed to proceed and an alert is generated.

12. At least one non-transitory computer readable medium having instructions stored thereon, the instructions when executed by a processor cause the processor to:

intercept a registry action attempt indicating an action by a process on a registry entry;

determine an identifier for the process;

use the identifier to determine a program file representing instructions being executed by the process;

determine a network connectivity state of a computer, wherein at least one entry in an authorization policy designates an authorization of a particular action for the program file based on the network connectivity state and a type of action associated with the particular action, and wherein a network connectivity state parameter includes an attribute associated with whether the computer is connected to a wired network or a wireless network;

determine whether the action is authorized or not based on the authorization policy, wherein the authorization policy includes the network connectivity state parameter, a program file parameter, an object parameter, and an attempted action parameter;

allow the action by the process to proceed when the action is authorized, as indicated by the authorization policy; and

respond when a determination is made that the action is not authorized, wherein a response comprises one of a first mode and a second mode, when in the first mode the action is blocked and an alert is generated, the alert including the type of action and the network connectivity state at the time the action was attempted, and when in the second mode the action is allowed to proceed and an alert is generated.

13. At least one non-transitory computer readable medium having instructions stored thereon, the instructions when executed by a processor cause the processor to:

intercept an execution attempt indicating a process attempting to execute an executable file;

determine an identifier for the process;

use the identifier to determine a program file representing instructions being executed by the process;

determine a network connectivity state of the computer, wherein at least one entry in an authorization policy designates an authorization of a particular execution for the program file based on the network connectivity state and a type of execution associated with the particular execution, and wherein a network connectivity state parameter includes an attribute associated with whether the computer is connected to a wired network or a wireless network;

determine whether the execution is authorized or not based on the authorization policy, wherein the authorization policy includes the network connectivity state parameter, a program file parameter, an object parameter, and an attempted execution parameter;

allow the execution to proceed when the execution is authorized, as indicated by the authorization policy; and

respond when a determination is made that the execution is not authorized, wherein a response comprises one of a first mode and a second mode, when in the first mode the execution is blocked and an alert is generated, the alert including the type of action and the network connectivity state at the time the execution was attempted, and when in the second mode the execution is allowed to proceed and an alert is generated.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
MERGER Recorded Jul 20, 2009
From: SOLIDCORE SYSTEMS, INC.
To: MCAFEE, INC.
Reel/Frame 022973/0458 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2006
From: SEBES, E. JOHN; BHARGAVA, RISHI; REESE, DAVID P.
To: SOLIDCORE SYSTEMS, INC
Reel/Frame 017920/0740 →