IP Library Granted Patent US 8,966,624
Granted Patent B2
US 8,966,624 · App. 13/076,493 · Granted Feb 24, 2015

System and method for securing an input/output path of an application against malware with a below-operating system security agent

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,966,624
App. No.
13/076,493
Granted
Feb 24, 2015
Kind
B2
Abstract

A system for securing an electronic device may include a memory, a processor, one or more operating systems residing in the memory for execution by the processor, an input-output (I/O) device of the electronic device coupled to the operating system; and a security agent configured to execute on the electronic device at a level below all of the operating systems of the electronic device accessing the I/O device. The security agent may be further configured to: (i) trap, at a level below all of the operating systems of the electronic device accessing an input/output (I/O) device, an attempted access of a facility for I/O operation with the I/O device; and (ii) using one or more security rules, analyze the attempted access to determine whether the attempted access is indicative of malware.

Claims (83)

1. A method for securing an electronic device, the electronic device including one or more operating systems and an input/output (I/O) device, comprising:

trapping, at a level below all of the operating systems of the electronic device, an I/O operation to the I/O device by an application;

in response to trapping the I/O operation, intercepting, at a level below all of the operating systems of the electronic device, original content of the I/O operation;

modifying and replacing, at a level below all of the operating systems of the electronic device, the original content of the I/O operation with modified content for transmission via an application I/O path of the I/O operation;

intercepting, at a level below all of the operating systems of the electronic device, the modified content after transmission via the application I/O path; and

analyzing, at a level below all of the operating systems of the electronic device, the intercepted modified content to determine whether the modified content was affected by malware during transmission via the application I/O path, wherein determining whether the modified content was affected comprises:

transmitting the original content in a different path in parallel with the modified content; and

comparing the intercepted modified content with the modified content to determine whether any differences exist between the intercepted modified content and the modified content, such differences indicating that the modified content was affected by malware.

2. A method according to claim 1 , further comprising: replacing, at a level below all of the operating systems of the electronic device, the intercepted modified content transmitted via the application I/O path with the original content; and transmitting, at a level below all of the operating systems of the electronic device accessing the I/O device, the original content of the I/O operation to the I/O device without transmission via the application I/O path.

3. A method according to claim 1 , further comprising initiating, at a level below all of the operating systems of the electronic device, corrective action in response to determining that the modified content was affected by malware during transmission via the application I/O path.

4. A method according to claim 3 , wherein initiating corrective action comprises communicating forensic evidence to a protection server.

5. A method according to claim 3 , wherein initiating corrective action comprises at least one of removing, quarantining, and neutralizing the malware.

6. A method according to claim 1 , further comprising: determining whether the application I/O path is vulnerable to malware attack; and performing the trapping, intercepting, modifying, and analyzing steps in response to a determination that the application I/O path is vulnerable to malware attack.

7. A method according to claim 1 , further comprising: spoofing access to the electronic device accessible via a network using the modified content for transmission via the application I/O path; and analyzing, by the electronic device, actions taken during spoofed access to the electronic device to determine if a second electronic device including the application I/O path is infected by malware.

8. A system for securing an electronic device, comprising:

a memory;

a processor;

one or more operating systems residing in the memory for execution by the processor;

an input-output (I/O) device of the electronic device coupled to the one or more operating systems; and

a security agent configured to execute on the electronic device at a level below all of the operating systems of the electronic device, the security agent further configured to:

trap an I/O operation to a device by an application;

in response to trapping the I/O operation, intercept original content of the I/O operation;

modify and replace the original content of the I/O operation with modified content for transmission via an application I/O path of the I/O operation;

intercept the modified content after transmission via the application I/O path; and

analyze the intercepted modified content to determine whether the modified content was affected by malware during transmission via the application I/O path, wherein determining whether the modified content was affected comprises:

transmitting the original content in a different path in parallel with the modified content; and

comparing the intercepted modified content with the modified content to determine whether any differences exist between the intercepted modified content and the modified content, such differences indicating that the modified content was affected by malware.

9. A system according to claim 8 , the security agent further configured to: replace the intercepted modified content transmitted via the application I/O path with the original content; and transmit the original content of the I/O operation to the I/O device without transmission via the application I/O path.

10. A system according to claim 8 , the security agent further configured to initiate corrective action in response to determining that the modified content was affected by malware during transmission via the application I/O path.

11. A system according to claim 10 , the security agent further configured to communicate forensic evidence to a protection server in order to initiate corrective action.

12. A system according to claim 10 , the security agent further configured to perform at least one of removing, quarantining, and neutralizing the malware in order to initiate corrective action.

13. A system according to claim 8 , the security agent further configured to: determine if the application I/O path is vulnerable to malware attack; and trap, intercept, modify, and analyze in response to a determination that the application I/O path is vulnerable to malware attack.

14. A system according to claim 8 , wherein: the security agent is further configured to spoof access to the electronic device accessible via a network using the modified content for transmission via the application I/O path; and the electronic device is configured to analyze actions taken during spoofed access to the electronic device to determine if a second electronic device including the application I/O path is infected by malware.

15. An article of manufacture, comprising:

a non-transitory computer readable medium; and

computer-executable instructions carried on the non-transitory computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to, at a level below all operating systems of an electronic device, the electronic device including one or more operating systems and an input/output (I/O) device:

trap an I/O operation to the I/O device by an application;

in response to trapping the I/O operation, intercept original content of the I/O operation;

modify and replace the original content of the I/O operation with modified content for transmission via an application I/O path of the I/O operation;

intercept the modified content after transmission via the application I/O path; and

analyze the intercepted modified content to determine whether the modified content was affected by malware during transmission via the application I/O path, wherein determining whether the modified content was affected comprises:

transmitting the original content in a different path in parallel with the modified content; and

comparing the intercepted modified content with the modified content to determine whether any differences exist between the intercepted modified content and the modified content such differences indicating that the modified content was affected by malware.

16. An article according to claim 15 , wherein the processor is further caused to: replace the intercepted modified content transmitted via the application I/O path with the original content; and transmit the original content of the I/O operation to the I/O device without transmission via the application I/O path.

17. An article according to claim 15 , wherein the processor is further caused to initiate corrective action in response to determining that the modified content was affected by malware during transmission via the application I/O path.

18. An article according to claim 17 , wherein the processor is further caused to communicate forensic evidence to a protection server in order to initiate corrective action.

19. An article according to claim 17 , wherein the processor is further caused to perform at least one of removing, quarantining, and neutralizing the malware in order to initiate corrective action.

20. An article according to claim 15 , wherein the processor is further caused to: determine if the application I/O path is vulnerable to malware attack; and trap, intercept, modify, and analyze in response to a determination that application I/O path is vulnerable to malware attack.

21. An article according to claim 15 , wherein the processor is further caused to: spoof access to the electronic device accessible via a network using the modified content for transmission via the application I/O path; and analyze actions taken during spoofed access to the electronic device to determine if a second electronic device including the application I/O path is infected by malware.

22. A method for securing an electronic device, the electronic device including one or more operating systems and an input/output (I/O) device, comprising:

trapping, at a level below all of the operating systems of the electronic device, an attempted access of a facility for I/O operation with the I/O device; and

using one or more security rules, analyzing, at a level below all of the operating systems of the electronic device, the attempted access to determine whether the attempted access is indicative of malware, wherein determining whether the attempted access is indicative of malware comprises:

modifying original content of the attempted access with modified content for transmission via an application I/O path of the I/O operation;

transmitting the original content in a different path in parallel with the modified content;

intercepting the modified content after transmission via the application I/O path; and

comparing the intercepted modified content with the modified content to determine whether any differences exist between the modified content and the intercepted modified content, such differences indicating that the modified content was affected by malware.

23. The method of claim 22 , further comprising determining the identity of an entity that made the attempted access, wherein: the facility for I/O operation includes a function for I/O operation; and determining whether the attempted access is indicative of malware includes determining whether the entity is authorized to make the attempted access.

24. The method of claim 22 , further comprising: determining the identity of an entity that made the attempted access; wherein: the facility for I/O operation includes a data structure for I/O operation; and determining whether the attempted access is indicative of malware includes determining whether the entity is authorized to make the attempted access.

25. An article of manufacture, comprising:

a non-transitory computer readable medium; and

computer-executable instructions carried on the computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to, at a level below all operating systems of an electronic device, the electronic device including one or more operating systems and input/output (I/O) device:

trap, at a level below all of the operating systems of the electronic device, an attempted access of a facility for I/O operation with the I/O device; and

using one or more security rules, analyze, at a level below all of the operating systems of the electronic device, the attempted access to determine whether the attempted access is indicative of malware, wherein determining whether the attempted access is indicative of malware comprises:

modifying original content of the attempted access with modified content for transmission via an application I/O path of the I/O operation;

transmitting the original content in a different path in parallel with the modified content;

intercepting the modified content after transmission via the application I/O path; and

comparing the intercepted modified content with the modified content to determine whether any differences exist between the modified content and the intercepted modified content, such differences indicating that the modified content was affected by malware.

26. The article of claim 25 , wherein: the processor is further caused to determine the identity of an entity that made the attempted access; the facility for I/O operation includes a function for I/O operation; and determining whether the attempted access is indicative of malware includes determining whether the entity is authorized to make the attempted access.

27. The article of claim 25 , wherein: the process is further caused to determine the identity of an entity that made the attempted access; the facility for I/O operation includes a data structure for I/O operation; and determining whether the attempted access is indicative of malware includes determining whether the entity is authorized to make the attempted access.

28. A system for securing an electronic device, comprising:

a memory;

a processor;

one or more operating systems residing in the memory for execution by the processor;

an input-output (I/O) device of the electronic device coupled to the one or more operating systems; and

a security agent configured to execute on the electronic device at a level below all of the operating systems of the electronic device, the security agent further configured to:

trap, at a level below all of the operating systems of the electronic device, an attempted access of a facility for I/O operation with the I/O device; and

using one or more security rules, analyze, at a level below all of the operating systems of the electronic device, the attempted access to determine whether the attempted access is indicative of malware, wherein determining whether the attempted access is indicative of malware comprises:

modifying original content of the attempted access with modified content for transmission via an application I/O path of the I/O operation;

transmitting the original content in a different path in parallel with the modified content;

intercepting the modified content after transmission via the application I/O path; and

comparing the intercepted modified content with the modified content to determine whether any differences exist between the modified content and the intercepted modified content, such differences indicating that the modified content was affected by malware.

29. The system of claim 28 , wherein: the security agent is further caused to determine the identity of an entity that made the attempted access; the facility for I/O operation includes a function for I/O operation; and determining whether the attempted access is indicative of malware includes determining whether the entity is authorized to make the attempted access.

30. The system of claim 28 , wherein: the security agent is further caused to determine the identity of an entity that made the attempted access; the facility for I/O operation includes a data structure for I/O operation; and determining whether the attempted access is indicative of malware includes determining whether the entity is authorized to make the attempted access.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 31, 2011
From: SALLAM, AHMED SAID
To: MCAFEE, INC.
Reel/Frame 026056/0761 →