IP Library Granted Patent US 9,734,333
Granted Patent B2
US 9,734,333 · App. 13/841,245 · Granted Aug 15, 2017

Information security techniques including detection, interdiction and/or mitigation of memory injection attacks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,734,333
App. No.
13/841,245
Granted
Aug 15, 2017
Kind
B2
Abstract

Methods of detecting malicious code injected into memory of a computer system are disclosed. The memory injection detection methods may include enumerating memory regions of an address space in memory of computer system to create memory region address information. The memory region address information may be compared to loaded module address information to facilitate detection of malicious code memory injection.

Claims (56)

1. A method comprising:

(a) enumerating, based on a query of an operating executive of a computer system, a plurality of memory regions of an address space in memory of the computer system, thereby creating memory region address information; and

(b) scanning memory of the computer system for a memory injection, wherein the scanning step comprises:

(i) determining whether a first memory region of the plurality of memory regions corresponds to any of a plurality of loaded modules registered with the operating executive, wherein the determining step comprises:

examining the plurality of loaded modules for loaded module address information; and

comparing the memory region address information to the loaded module address information, wherein start and end addresses of each loaded module of the plurality of loaded modules are compared to start and end addresses of the first memory region; and

(ii) wherein, when the first memory region does not correspond to any of the plurality of loaded, determining whether the first memory region contains library indicative coding, the first memory region does not correspond to any of the plurality of loaded modules when each loaded module from the plurality of loaded modules lies completely outside the start and end address of first memory region; and

(iii) wherein, when the first memory region contains library indicative coding, generating a memory injection alarm.

2. The method of claim 1 , wherein, when the first memory region corresponds to one of the plurality of loaded modules, determining whether that loaded module is mapped from a file system of the computer system.

3. The method of claim 2 , wherein the memory injection alarm is a first memory injection alarm, and wherein, when the loaded module is not mapped from a file system of the computer system, generating a second memory injection alarm.

4. The method of claim 3 , wherein the first memory injection alarm is indicative of a reflective dynamic link library memory injection.

5. A method comprising:

(a) enumerating, based on a query of an operating executive of a computer system, a plurality of memory regions of an address space in memory of the computer system, thereby creating memory region address information; and

(b) scanning memory of the computer system for a memory injection, wherein the scanning step comprises:

(i) determining whether a first memory region of the plurality of memory regions corresponds to any of a plurality of loaded modules registered with the operating executive, wherein the determining step comprises:

examining the plurality of loaded modules for loaded module address information; and

comparing the memory region address information associated with the first memory region to the loaded module address information, wherein start and end addresses of each loaded module of the plurality of loaded modules are compared to start and end addresses of the first memory region; and

(ii) wherein, when the first memory region corresponds to one of the plurality of loaded modules, determining whether that loaded module is mapped from a file system of the computer system, the first memory region does not correspond to that loaded module when that loaded module lies completely outside the start and end address of first memory region; and

(iii) wherein, when the loaded module is not mapped from a file system of the computer system, generating a memory injection alarm.

6. The method of claim 5 , wherein the scanning step comprises:

determining whether the first memory region is in use by ensuring that it is committed memory; and

wherein, when the first memory region is in use, determining whether the first memory region corresponds to any of the plurality of loaded modules.

7. The method of claim 5 , wherein the scanning step comprises:

determining whether the first memory region is at least one of a read, write, or executable region or was initially allocated as at least one of a read, write, or executable region; and

wherein, when the first memory region is at least one of a read, write, or executable region or was initially allocated as at least one of a read, write, or executable region, determining whether the first memory region contains library indicative coding.

8. The method of claim 5 , wherein the operating executive includes an operating system.

9. The method of claim 5 , wherein the query comprises:

obtaining a process handle for each process executing on the computer system; and

based on the obtained process handle, querying the operating executive to obtain at least a respective base address and size for each of successive memory regions within the address space of the respective process.

10. The method of claim 9 , wherein the querying step comprises: obtaining from the operating executive an identifier for the respective file system object, if any, from which content of a particular memory region is mapped.

11. The method of claim 9 , wherein the process handle obtaining includes:

maintaining a shadow process table in correspondence with start of new processes or threads; and accessing the maintained shadow process table.

12. The method of claim 9 , wherein the process handle obtaining includes:

accessing a process table maintained by the operating executive.

13. The method of claim 5 , wherein the comparing step is performed at successive times during operation of the computer system.

14. The method of claim 5 , comprising:

at least for memory regions allocated to a given process, performing the comparing step in response to an event, wherein the event is at least one of:

(i) start of a new process or thread;

(ii) a network-facing socket operation;

(iii) creation of a new binary on a file system; or

(iv) the expiration of a polling timer.

15. The method of claim 5 , wherein the query comprises walking a call stack.

16. The method of claim 5 , further comprising: performing at least the comparing and the determining in kernel code.

17. The method of claim 5 ,

wherein for at least some executions, the comparing is limited to those address space regions having a trust-execute protection object.

18. The method of claim 5 , wherein the enumerating step comprises:

enumerating, based on the query, the plurality of loaded modules, thereby creating loaded module address information.

19. The method of claim 5 , wherein

when a loaded module from the plurality of loaded modules spans the first memory region, or partially overlaps the first memory region, then the loaded module corresponds to the first memory region.

20. A security method for a computational system, the method comprising:

querying an operating executive of the computational system to populate a data structure that enumerates regions of an address space allocated to processes executing on the computational system;

querying the operating executive to populate a data structure that enumerates a set of loaded modules registered with the operating executive;

comparing the enumerated address space regions against the enumerated set of loaded modules, the comparing comprising comparing start and end addresses of each loaded module of the set of loaded modules to start and end addresses of the enumerated address space regions;

for those of the enumerated address space regions that correspond to a loaded module registered with the operating executive, checking for absence of a mapping from a file system object, the enumerated address space region from the enumerated address space regions does not correspond to a loaded module from the set of loaded modules when that loaded module lies completely outside the start and end address of the enumerated address space region; and

responsive to detection of no mapping from a file system object, generating a detection event.

21. The method of claim 1 , wherein the enumerating comprises populating entries in at least one process tracking table.

Assignments (22)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2025
From: IVANTI SECURITY HOLDINGS LLC
To: IVANTI, INC.
Reel/Frame 071958/0203 →
2025-1 SECOND LIEN SECURITY AGREEMENT Recorded May 5, 2025
From: IVANTI SECURITY INTERMEDIATE HOLDINGS LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0498 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2025
From: IVANTI, INC.
To: IVANTI SECURITY HOLDINGS LLC
Reel/Frame 071180/0690 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
PARTIAL RELEASE OF SECURITY INTERESTS Recorded May 5, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; CHERWELL SOFTWARE, LLC
Reel/Frame 071176/0289 →
SECURITY INTEREST Recorded May 3, 2025
From: IVANTI SECURITY HOLDINGS LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0164 →
RELEASE OF SECURITY INTEREST Recorded May 2, 2025
From: ALTER DOMUS (US) LLC
To: IVANTI SECURITY HOLDINGS LLC
Reel/Frame 071162/0130 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41459/0436 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: HEAT SOFTWARE USA INC.
Reel/Frame 054560/0713 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41052/0735 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: HEAT SOFTWARE USA INC.
Reel/Frame 054560/0744 →
MERGER Recorded Apr 19, 2018
From: HEAT SOFTWARE USA INC.
To: IVANTI, INC.
Reel/Frame 045589/0203 →
RELEASE OF SECURITY INTERESTS IN PATENTS AT REEL/FRAME NO. 33380/0644 Recorded Jan 21, 2017
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: HEAT SOFTWARE USA INC., AS SUCCESSOR IN INTEREST TO LUMENSION SECURITY, INC.
Reel/Frame 041052/0794 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: HEAT SOFTWARE USA INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041052/0735 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: HEAT SOFTWARE USA INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041459/0436 →
MERGER AND CHANGE OF NAME Recorded Jan 18, 2017
From: LUMENSION SECURITY INC.; HEAT SOFTWARE USA INC.
To: HEAT SOFTWARE USA INC.
Reel/Frame 041010/0854 →
RELEASE OF SECURITY INTEREST Recorded Oct 25, 2016
From: CONSORTIUM FINANCE, LLC
To: NETMOTION WIRELESS HOLDINGS, INC.; NETMOTION WIRELESS, INC.; LUMENSION SECURITY, INC.
Reel/Frame 040479/0001 →
PATENT SECURITY AGREEMENT (SECOND LIEN) Recorded Jul 23, 2014
From: NETMOTION WIRELESS HOLDINGS, INC.; NETMOTION WIRELESS, INC.; LUMENSION SECURITY, INC.
To: CONSORTIUM FINANCE, LLC
Reel/Frame 033381/0536 →
PATENT SECURITY AGREEMENT Recorded Jul 22, 2014
From: LUMENSION SECURITY, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 033380/0644 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 15, 2013
From: TEAL, DANIEL
To: LUMENSION SECURITY, INC.
Reel/Frame 030800/0124 →