IP Library Granted Patent US 9,268,936
Granted Patent B2
US 9,268,936 · App. 13/560,415 · Granted Feb 23, 2016

Physical memory forensics system and method

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,268,936
App. No.
13/560,415
Granted
Feb 23, 2016
Kind
B2
Abstract

The method of the present inventive concept is configured to utilize Operating System data structures related to memory-mapped binaries to reconstruct processes. These structures provide a system configured to facilitate the acquisition of data that traditional memory analysis tools fail to identify, including by providing a system configured to traverse a virtual address descriptor, determine a pointer to a control area, traverse a PPTE array, copy binary data identified in the PPTE array, generate markers to determine whether the binary data is compromised, and utilize the binary data to reconstruct a process.

Claims (47)

1. A method to determine whether a computer system has been compromised, the method comprising the steps of:

traversing a virtual address descriptor to acquire process data;

reconstructing mapped data based on the acquired process data;

storing the mapped data via a memory of a system, and

traversing a virtual address control block to recover a file from a memory cache if (i) a page table entry is invalid, and (ii) a valid data length related to the file is not determined to be greater than a size of the file,

wherein,

the mapped data is obtained when a virtual address causes a page fault, and

the page fault triggers the system to execute a process to automatically acquire the mapped data.

2. The method of claim 1 , wherein the traversing the virtual address descriptor includes (i) traversing at least one descendant lineage to a terminal node using at least one pointer and at least one node, and (ii) retrieving data associated with the at least one node.

3. The method of claim 2 , wherein the pointer is a SECTION_OBJECT_POINTER structure having (i) a first pointer named ImageSectionObject, (ii) a second pointer named DataSectionObject, and (iii) a third pointer named SharedCacheMap.

4. The method of claim 1 , further comprising the step of:

generating, via a processor of the system, at least one marker based on the mapped data.

5. The method of claim 4 , wherein the marker is a set of hashes.

6. The method of claim 4 , further comprising the step of:

comparing, vit the processor, the at least one marker to another marker to determine whether a compromise exists within the system.

7. The method of claim 6 , wherein the another marker is based on binary data of known uncompromised data.

8. The method of claim 7 , wherein the another marker is a set of hashes.

9. The method of claim 6 , further comprising the step of:

determining whether the mapped data is compromised based on the comparison.

10. The method of claim 1 , further comprising the step of:

executing a hashing process to produce a plurality of hash values based on the mapped data;

comparing the plurality of hash values with a set of control values and producing a result; and

determining whether the mapped data is compromised based on the result.

11. A method of reconstructing a process using a computer system, the method comprising the steps of:

traversing a virtual address descriptor to acquire process data;

reconstructing mapped data based on the acquired process data;

storing the mapped data via a memory of the computer system, and

traversing a virtual address control block to recover a file from a memory cache if (i) a page table entry is invalid, and (ii) a valid data length related to the file is not determined to be greater than a size of the file,

wherein,

the mapped data is obtained when a virtual address causes a page fault, and

the page fault triggers the computer system to execute a process to automatically acquire the mapped data.

12. The method of claim 11 , wherein the traversing the virtual address descriptor includes (i) traversing at least one descendant lineage to a terminal node using at least one pointer and at least one node, and (ii) retrieving data associated with the at least one node.

13. The method of claim 12 , wherein the pointer is a SECTION_OBJECT_POINTER structure having (i) a first pointer named ImageSectionObject, (ii) a second pointer named DataSectionObject, and (iii) a third pointer named SharedCacheMap.

14. The method of claim 11 , further comprising the step of:

generating, via a processor, at least one marker based on the mapped data,

wherein,

the marker is a set of hashes.

15. The method of claim 14 , further comprising the step of:

comparing, via the processor, the at least one marker to another marker to determine whether a compromise exists,

wherein the another marker is based on binary data of known uncompromised data.

16. The method of claim 15 , wherein the another marker is a set of hashes.

17. The method of claim 15 , further comprising the step of:

determining whether the mapped data is compromised based on the comparison.

18. The method of claim 11 , further comprising the step of:

executing a hashing process to produce a plurality of hash values based on the mapped data;

comparing the plurality of hash values with a set of control values and producing a result; and

determining whether the mapped data is compromised based on the result.

Assignments (16)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063287/0707 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063287/0702 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 12, 2016
From: MANDIANT, LLC
To: FIREEYE, INC.
Reel/Frame 038569/0165 →
CHANGE OF NAME Recorded Mar 5, 2014
From: MERCURY MERGER LLC
To: MANDIANT, LLC
Reel/Frame 032351/0340 →
MERGER Recorded Mar 4, 2014
From: MANDIANT CORPORATION
To: MERCURY MERGER LLC
Reel/Frame 032342/0806 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2012
From: BUTLER, JAMES
To: MANDIANT CORPORATION
Reel/Frame 029129/0808 →