IP Library Granted Patent US 8,938,802
Granted Patent B2
US 8,938,802 · App. 13/932,888 · Granted Jan 20, 2015

System and method for run-time attack prevention

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,938,802
App. No.
13/932,888
Granted
Jan 20, 2015
Kind
B2
Abstract

Preventing attacks on a computer at run-time. Content that is configured to access at least one function of a computer is received by the computer. Protections corresponding to the function are added to the content, wherein the protections override the function. The content and the protections are then transmitted to the computer. The function may expose a vulnerability of the computer, and arguments passed to the function may exploit that vulnerability. The protections are executed when the content is executed, and determine whether the arguments the content passed into the function represent a threat. In response to determining that the arguments represent a threat, execution of the content is terminated without executing the function.

Claims (49)

1. A system for protecting a computer, wherein the system is coupled to a network and to the computer, the system comprising:

a memory including code; and

a processor for executing code to:

receive processor executable content requested by the computer from a content server, wherein the processor executable content is configured to access a system function of the computer and includes an argument a plurality of arguments;

determine a computing environment associated with the computer;

identify a computer threat protection corresponding with the computing environment;

add the computer threat protection to the processor executable content; and

transmit the protection and the processor executable content to the computer;

wherein the computer threat protection is configured to be executed by the computer in response to a call to the system function, to:

analyze the arguments to determine whether a combination of the arguments comprises a threat to the computer if passed into the system function;

modify the execution of the processor executable content in response to determining that the combination of arguments comprises a threat to the computer; and

allow the system function to execute as called by the processor executable content in response to determining that the combination of arguments do not comprise a threat to the computer.

2. The system of claim 1 , wherein in modifying the execution of the processor executable content, the computer threat protection is further configured to terminate the execution of the processor executable content.

3. The system of claim 1 , wherein in modifying the execution of the processor executable content, the computer threat protection is further configured to provide an alert in response to determining that the combination of arguments argument comprises a threat.

4. The system of claim 3 , wherein the alert is provided to one of an end user and a network administrator.

5. The system of claim 1 , wherein:

the processor further executes code to determine a type of the processor executable content; and

the computer threat protection corresponding with the type.

6. The system of claim 1 , wherein the processor executable content comprises one of JavaScript, Flash, and Silverlight.

7. The system of claim 1 , wherein the processor executable content comprises ASCII text that is executed upon receipt by the computer.

8. A system for protecting a computer, comprising:

a content server configured to provide processor executable content;

a computer remote from the content server and configured to receive the processor executable content from the content server, wherein the processor executable content is configured to access a system function of the computer;

a protection engine remote from the content server and from the computer, and configured to:

determine a computing environment associated with the computer;

identify a computer threat protection corresponding with the computing environment;

receive the processor executable content before the processor executable content is received by the computer;

add the computer threat protection to the processor executable content;

transmit the computer threat protection and the processor executable content to the computer;

determine whether an argument a combination of a plurality of arguments of the processor executable content represent a threat to the computer if the argument combination of arguments is passed to the system function; and

execute the computer threat protection in response to determining that the combination of arguments argument represents a threat.

9. The system of claim 8 , wherein adding the computer threat protection to the processor executable content comprises prepending adding the computer threat protection to the content.

10. The system of claim 8 , wherein the content server comprises the protection engine.

11. The system of claim 8 , wherein the content server comprises the computer.

12. The system of claim 8 , wherein the computer threat protection is configured to modify the processor executable content upon determining that the system function comprises a threat.

13. The system of claim 8 , wherein the computer threat protection is configured to terminate the execution of the processor executable content upon determining that the system function comprises a threat.

14. The system of claim 8 , wherein the computer threat protection is configured to alert one of an end user and a network administrator upon determining that the system function comprises a threat.

15. A method comprising:

determining, at a protection device, a computer environment associated with a computer;

identifying, at the protection device, a computer threat protection corresponding with the computing environment, wherein the computer threat protection overrides a system function of the computer;

intercepting, by the protection device, processor executable content from a content server, the content being executable by the computer to access the system function of the computer;

adding the computer threat protection to the processor executable content;

transmitting, from the protection device, the computer threat protection and the processor executable content to the computer; and

executing, at the computer, the computer threat protection in response to a call to the system function by the processor executable content, wherein executing the computer threat protection comprises determining whether an argument a combination of a plurality of arguments of the processor executable content passed into the system function represent a threat to the computer.

16. The method of claim 15 , further comprising terminating the execution of the processor executable content in response to determining that the argument combination of arguments represents a threat.

17. The method of claim 15 , further comprising modifying the processor executable content in response to determining that the combination of arguments argument represents a threat.

18. The method of claim 15 , further comprising alerting one of an end user and a network administrator in response to determining that the combination of arguments argument represents a threat.

19. The method of claim 15 , wherein the processor executable content comprises one of JavaScript, Flash, and Silverlight.

20. The method of claim 15 , wherein adding the computer threat protection comprises adding the computer threat protection.

Assignments (11)
SECURITY INTEREST Recorded May 2, 2025
From: SECUREWORKS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 071009/0116 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 9, 2025
From: DAVENPORT, ANDY; KING, HUNTER; RAMSEY, JON R.
To: SECUREWORKS, INC.
Reel/Frame 070784/0110 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2015
From: BANK OF AMERICA, N.A.
To: SECUREWORKS HOLDING CORPORATION; SECUREWORKS, INC.
Reel/Frame 036262/0490 →
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2015
From: BANK OF AMERICA, N.A.
To: SECUREWORKS HOLDING CORPORATION; SECUREWORKS, INC.
Reel/Frame 036262/0509 →
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2015
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: SECUREWORKS HOLDING CORPORATION; SECUREWORKS, INC.
Reel/Frame 036262/0525 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →