IP Library Granted Patent US 8,938,805
Granted Patent B1
US 8,938,805 · App. 13/625,497 · Granted Jan 20, 2015

Detection of tampering with software installed on a processing device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,938,805
App. No.
13/625,497
Granted
Jan 20, 2015
Kind
B1
Abstract

A processing device comprises a processor coupled to a memory and implements a host-based intrusion detection system configured to permit detection of tampering with at least one software component installed on the processing device. The host-based intrusion detection system comprises a forward-secure logging module configured to record information characterizing a plurality of events occurring in the device in such a manner that modification of the recorded information characterizing the events is indicative of a tampering attack and can be detected by an authority. For example, the recorded information may comprise at least one forward-secure logging record R having entries r 1 . . . r n corresponding to respective ones of the events wherein any erasure or other modification of a particular pre-existing entry r i in R by an attacker is detectable by the authority upon inspection of R.

Claims (38)

1. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the processing device implementing a host-based intrusion detection system configured to permit detection of tampering with at least one software component installed on the processing device;

the host-based intrusion detection system comprising a forward-secure logging module configured to record information characterizing a plurality of events occurring in the device in such a manner that modification of the recorded information characterizing the events is indicative of a tampering attack and can be detected by an authority;

wherein the forward-secure logging module is configured to perform said recording in a concealed manner that cannot be directly correlated with occurrence of at least one of the plurality of events; and

wherein the host-based instruction detection system is configured to send, in response to randomly-timed requests, respective different portions of the forward-secure logging records to the authority such that the forward-secure logging records cannot be directly correlated with occurrence of the corresponding events.

2. The apparatus of claim 1 wherein the forward-secure logging module is configured to record said information without requiring any connection between the processing device and a network.

3. The apparatus of claim 1 wherein the forward-secure logging module is configured to record said information even if an entity carrying out the tampering attack has physical possession of the processing device.

4. The apparatus of claim 1 wherein the forward-secure logging module is configured to record the information characterizing the plurality of events in the form of at least one forward-secure logging record R having entries r 1 . . . r n corresponding to respective ones of the events wherein any erasure or other modification of a particular pre-existing entry r i in R by an attacker is detectable by the authority upon inspection of R, where i is an index that can take on integer values from 1 to n.

5. The apparatus of claim 1 wherein:

the forward-secure logging module is instrumented with one or more predetermined signatures each indicative of one or more events likely to occur in conjunction with a particular type of tampering attack; and

the forward-secure logging module is configured, responsive to detecting one or more events likely to occur in conjunction with a given one of the particular types of tampering attack, to record the one or more events as a given one of the predetermined signatures indicative of the given particular type of tampering attack.

6. The apparatus of claim 1 wherein the host-based intrusion detection system is configured to communicate the respective different portions of the forward-secure logging records to the authority over a network.

7. The apparatus of claim 4 wherein said modification indicative of a tampering attack can be detected by an authority through comparison of the forward-secure logging record R to one or more attack-specific templates stored by the authority.

8. The apparatus of claim 1 wherein the host-based intrusion detection system comprises a plurality of intrusion detection sensors implemented in an operating system layer or a lower layer of an executable software stack of the processing device with each such sensor configured to detect events of a particular type.

9. The apparatus of claim 1 wherein the events are behaviorally related to compromise of a running software kernel of the processing device.

10. The apparatus of claim 1 wherein the processing device is configured to communicate with a server of said authority and wherein said server generates an alert based on detection of the tampering attack.

11. The apparatus of claim 1 wherein the recorded information comprises an indication of placement of the processing device into a maintenance mode at a time when the processing device would not normally be placed into the maintenance mode absent a tampering attack.

12. A method comprising the steps of:

recording information characterizing a plurality of events occurring in a processing device using a forward-secure logging module of the processing device; and

providing the recorded information to an authority;

wherein the recording step comprises recording the information characterizing the events in such a manner that modification of the recorded information is indicative of a tampering attack and can be detected by the authority;

wherein the recording step comprises using the forward-secure logging module to perform said recording in a concealed manner that cannot be directly correlated with occurrence of at least one of the plurality of events; and

wherein the providing step comprises sending, in response to randomly-timed requests, respective different portions of the recorded information to the authority such that the recorded information cannot be directly correlated with occurrence of the corresponding events.

13. The method of claim 12 wherein the recording step comprises recording the information characterizing the plurality of events in the form of at least one forward-secure logging record R having entries r 1 . . . r n corresponding to respective ones of the events wherein any erasure or other modification of a particular pre-existing entry r i in R by an attacker is detectable by the authority upon inspection of R, where i is an index that can take on integer values from 1 to n.

14. The method of claim 12 wherein:

the forward-secure logging module is instrumented with one or more predetermined signatures each indicative of one or more events likely to occur in conjunction with a particular type of tampering attack; and

the recording step comprises, responsive to detecting the one or more events likely to occur in conjunction with a given one of the particular types of tampering attack, recording the one or more events as a given one of the predetermined signatures indicative of the given particular type of tampering attack.

15. A computer program product comprising a non-transitory processor-readable storage medium having encoded therein executable code of one or more software programs, wherein the one or more software programs when executed by said processing device cause the steps of the method of claim 12 to be performed.

16. An information processing system comprising:

at least one processing device; and

an authority adapted for communication with the processing device;

the processing device implementing a host-based intrusion detection system configured to permit detection of tampering with at least one software component installed on the processing device;

the host-based intrusion detection system comprising a forward-secure logging module configured to record information characterizing a plurality of events occurring in the device in such a manner that modification of the recorded information characterizing the events is indicative of a tampering attack and can be detected by the authority;

wherein the forward-secure logging module is configured to perform said recording in a concealed manner that cannot be directly correlated with occurrence of at least one of the plurality of events; and

wherein the host-based instruction detection system is configured to send, in response to randomly-timed requests, respective different portions of the forward-secure logging records to the authority such that the forward-secure logging records cannot be directly correlated with occurrence of the corresponding events.

17. The information processing system of claim 16 wherein the authority comprises at least one server.

18. The apparatus of claim 11 wherein the maintenance mode comprises a device firmware updated (DFU) mode.

Assignments (23)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
NOTICE OF PARTIAL TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN TRADEMARK RIGHTS AND PATENT RIGHTS RECORDED AT REEL/FRAME: 056098/0534 Recorded Jun 3, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 071484/0819 →
NOTICE OF PARTIAL TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN TRADEMARK RIGHTS AND PATENT RIGHTS RECORDED AT REEL/FRAME: 056096/0525 Recorded Jun 3, 2025
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC
Reel/Frame 071482/0733 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2025
From: RSA SECURITY LLC
To: NETWITNESS SECURITY LLC
Reel/Frame 071495/0168 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 24, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXRESS, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054511/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: ASAP SOFTWARE EXPRESS; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054163/0416 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2013
From: JUELS, ARI; HART, CATHERINE V.
To: EMC CORPORATION
Reel/Frame 029761/0385 →