IP Library Granted Patent US 9,275,229
Granted Patent B2
US 9,275,229 · App. 13/421,843 · Granted Mar 1, 2016

System to bypass a compromised mass storage device driver stack and method thereof

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,275,229
App. No.
13/421,843
Granted
Mar 1, 2016
Kind
B2
Abstract

A method to circumvent malicious software via a system configured to bypass a device driver stack and, consequently, also bypass the malicious software that may be adversely affecting the device driver stack by using an alternative stack such as a crash dump I/O stack. The crash dump I/O stack is poorly documented relative to the device driver stack and functions independently from the device driver stack.

Claims (78)

1. A method to circumvent malicious software in a computing device, the method comprising the steps of:

identifying a dump port driver having a function;

transmitting at least one command configured to obtain information related to a physical hardware device, the physical hardware device (i) in communication with the computing device and (ii) configured to execute an I/O command;

exploiting data from an information leak to (i) locate a dump port device extension and (ii) initialize a memory space; and

causing the function to be executed for transmission of the I/O command to the physical hardware device.

2. The method according to claim 1 , wherein the physical hardware device includes a mass storage area.

3. The method of claim 2 , further comprising the step of:

initializing a request block to specify a READ command or specify a WRITE command.

4. The method according to claim 1 ,

wherein,

the physical hardware device is a mass storage device, and

the identification of the dump port driver includes searching a loaded module list for one of a plurality of names to identify the dump port driver for the mass storage device.

5. The method according to claim 4 , wherein the one of the plurality of names contains a prefix.

6. The method according to claim 4 , wherein the identification of the dump port driver includes verifying the identified dump port driver is correct by parsing an export table.

7. The method according to claim 1 , wherein the physical hardware device is a mass storage device configured to contain debugging data for use during a critical system crash of the computing device.

8. The method according to claim 7 , wherein the debugging data is core dump data.

9. The method according to claim 1 , wherein the at least one command includes (i) a first command configured to obtain at least one of a target identification, a path, and a logical unit number, and (ii) a second command configured to obtain a hardware register.

10. The method according to claim 1 , wherein the function is at least one of a start in/out function and a DispatchCrb function.

11. The method of claim 1 ,

wherein,

the data is a memory pointer to the dump port device extension.

12. The method of claim 1 ,

wherein,

the dump port device extension is located by calling to a function of the dump port driver and receiving the dump port device extension address.

13. A method to circumvent malicious software in a computing device via a physical hardware device linked to a computing device, the method comprising:

identifying a dump port driver;

getting boot device information to enable transmission of an I/O command to a boot device;

determining an entry point for a function for transmitting the command to the physical hardware device;

exploiting data from an information leak to (i) locate a dump port device extension and (ii) initialize a memory space; and

causing the function to be executed for transmission of the command to the physical hardware device.

14. The method of claim 13 ,

wherein,

the data is a memory pointer to the dump port device extension.

15. The method of claim 13 ,

wherein,

the dump port device extension is located by (i) calling to a function of the dump port driver and (ii) receiving a dump port device extension address.

16. The method of claim 13 ,

wherein,

the physical hardware device is a mass storage device, and

further comprising the step of initializing a request block to specify a READ command or specify a WRITE command.

17. The method of claim 13 ,

wherein,

the data is from an internal source that is unintentionally exposed to an external source.

18. A system to command a physical hardware device in communication with a computing device, the system comprising:

a bypass command driver configured to identify a dump port driver, obtain boot device information, find a function, locate a dump port device extension and initialize a memory space, and call the function, the dump port driver in communication with the bypass command driver;

a computer program comprising the function, the function configured to transmit a command to the physical hardware device;

a mini port driver in communication with the dump port driver;

a bus driver in communication with the mini port driver and the dump port driver;

a hardware bus in communication with the bus driver; and

a physical hardware device in communication with the hardware bus,

wherein,

the bypass command driver is configured to locate the dump port device extension using data obtained from an information leak.

19. The system of claim 18 , wherein the function is configured (i) for storage in the dump port driver and (ii) to transmit the command via the bus driver.

20. The system of claim 18 , further comprising:

a request block that includes a command descriptor block configured to be initialized with the command.

21. The system of claim 18 ,

wherein,

the physical hardware device is a mass storage device, and

the command is a READ or a WRITE command.

22. The system of claim 18 , wherein the physical hardware device is a boot device.

23. The system of claim 18 , further comprising:

a memory space to send or receive data transferred as a result of execution of the command.

24. The system of claim 18 ,

wherein,

the bypass command driver is configured to execute an operation to exploit the information leak.

25. The system of claim 18 ,

wherein,

the operation to exploit the information leaked is executed by after executing an operation to obtain boot device information.

26. The system of claim 18 ,

wherein,

the data is from an internal source that is unintentionally exposed to an external source.

27. A method to circumvent malicious software in a computing device, the method comprising the steps of:

identifying a dump port driver having a function;

transmitting at least one command configured to obtain information related to a physical hardware device, the physical hardware device (i) in communication with the computing device and (ii) configured to execute an I/O command;

locating a dump port device extension using an information leak; and

causing the function to be executed for transmission of the I/O command to the physical hardware device,

wherein,

the information leak is data from an internal source that is unintentionally exposed to an external source.

Assignments (16)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063287/0707 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063287/0702 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 12, 2016
From: MANDIANT, LLC
To: FIREEYE, INC.
Reel/Frame 038569/0258 →
CHANGE OF NAME Recorded Mar 5, 2014
From: MERCURY MERGER LLC
To: MANDIANT, LLC
Reel/Frame 032351/0340 →
MERGER Recorded Mar 4, 2014
From: MANDIANT CORPORATION
To: MERCURY MERGER LLC
Reel/Frame 032342/0806 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 5, 2012
From: LEMASTERS, AARON
To: MANDIANT CORPORATION
Reel/Frame 028319/0412 →