IP Library Granted Patent US 8,613,093
Granted Patent B2
US 8,613,093 · App. 11/839,225 · Granted Dec 17, 2013

System, method, and computer program product for comparing an object with object enumeration results to identify an anomaly that at least potentially indicates unwanted activity

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,613,093
App. No.
11/839,225
Granted
Dec 17, 2013
Kind
B2
Abstract

A system, method, and computer program product are provided for comparing an object with object enumeration results to identify at least potentially unwanted activity. In use, a change in a state of an object is identified. Additionally, the object is compared with results of an object enumeration. Further, at least potentially unwanted activity is identified based on the comparison.

Claims (41)

1. A method for avoiding a false positive identification of an anomaly that potentially indicates unwanted activity based on an object that has been unlinked or deleted prior to identifying object enumeration results, comprising:

identifying a change in a state of the object via a filter driver of a security system, wherein the object is included in a predetermined list of objects of an operating system being monitored for object manipulation events;

determining whether the object has been unlinked or deleted;

if it is determined that the object has not been unlinked, determining whether results of an object enumeration have been identified by a kernel enumeration interface that utilizes a directory in which the object is expected to be included;

if it is determined that the results of the object enumeration have not been identified, determining repeatedly whether the object has been unlinked or deleted until the results of the object enumeration have been identified or in response to a determination that the object has been unlinked;

if the object has not been unlinked nor deleted and if the results of the object enumeration have been identified, comparing the object with results of the object enumeration;

if the object has been unlinked or deleted, preventing the comparing step;

identifying at least potentially unwanted activity based on the comparison, wherein the identifying includes identifying an anomaly associated with the object being removed from a particular list a kernel of the operating system is to utilize for the object enumeration; and

initiating an analysis of a process that requested the change in the state of the object, wherein the analysis is configured to identify a rootkit associated with the unwanted activity.

2. The method of claim 1 , wherein the object includes a file.

3. The method of claim 1 , wherein the object includes a registry.

4. The method of claim 1 , wherein the state of the object is changed as a result of an object manipulation request.

5. The method of claim 1 , wherein the state of the object includes an open state.

6. The method of claim 1 , wherein the state of the object includes a write state.

7. The method of claim 1 , wherein the change in the state of the object is identified by monitoring at least one application program interface.

8. The method of claim 1 , wherein the results of the object enumeration include a list of objects.

9. The method of claim 1 , wherein the object is compared with the results of the object enumeration based on a policy.

10. The method of claim 9 , wherein the policy indicates that for each of a plurality of objects for which a state has changed, the comparison is performed randomly.

11. The method of claim 9 , wherein the policy indicates that for each of a plurality of objects for which a state has changed, the comparison is performed only once per run-time.

12. The method of claim 1 , further comprising noting the comparison as successful in cache if it is determined that the object is included in the results of the object enumeration.

13. The method of claim 1 , wherein the at least potentially unwanted activity is identified if it is determined that the object does not match any portion of the results of the object enumeration.

14. A computer program product embodied on a non-transitory computer readable medium for performing operations for avoiding a false positive identification of an anomaly that potentially indicates unwanted activity based on an object that has been unlinked or deleted prior to identifying object enumeration results, the operations comprising:

identifying a change in a state of the object via a filter driver of a security system, wherein the object is included in a predetermined list of objects of an operating system being monitored for object manipulation events;

determining whether the object has been unlinked or deleted;

if it is determined that the object has not been unlinked, determining whether results of an object enumeration have been identified by a kernel enumeration interface that utilizes a directory in which the object is expected to be included;

if it is determined that the results of the object enumeration have not been identified, determining repeatedly whether the object has been unlinked or deleted until the results of the object enumeration have been identified or in response to a determination that the object has been unlinked;

if the object has not been unlinked nor deleted and if the results of the object enumeration have been identified, comparing the object with results of the object enumeration provided by a kernel enumeration interface that utilizes a directory in which the object is expected to be included;

if the object has been unlinked or deleted, preventing the comparing step;

identifying at least potentially unwanted activity based on the comparison, wherein the identifying includes identifying an anomaly associated with the object being removed from a particular list a kernel of the operating system is to utilize for the object enumeration; and

initiating an analysis of a process that requested the change in the state of the object, wherein the analysis is configured to identify a rootkit associated with the unwanted activity.

15. A system for avoiding a false positive identification of an anomaly that potentially indicates unwanted activity based on an object that has been unlinked or deleted prior to identifying object enumeration results, the system comprising:

a processor, wherein the system is configured for:

identifying a change in a state of the object via a filter driver of a security system, wherein the object is included in a predetermined list of objects of an operating system being monitored for object manipulation events;

determining whether the object has been unlinked or deleted;

if it is determined that the object has not been unlinked, determining whether results of an object enumeration have been identified by a kernel enumeration interface that utilizes a directory in which the object is expected to be included;

if it is determined that the results of the object enumeration have not been identified, determining repeatedly whether the object has been unlinked or deleted until the results of the object enumeration have been identified or in response to a determination that the object has been unlinked;

if the object has not been unlinked nor deleted and if the results of the object enumeration have been identified, comparing the object with results of the object enumeration;

if the object has been unlinked or deleted, preventing the comparing step;

identifying at least potentially unwanted activity based on the comparison, wherein the identifying includes identifying an anomaly associated with the object being removed from a particular list a kernel of the operating system is to utilize for the object enumeration; and

initiating an analysis of a process that requested the change in the state of the object, wherein the analysis is configured to identify a rootkit associated with the unwanted activity.

16. The system of claim 15 , wherein the processor is coupled to memory via a bus.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2007
From: CAMP, TRACY E.
To: MCAFEE, INC.
Reel/Frame 019701/0333 →