IP Library Granted Patent US 9,213,807
Granted Patent B2
US 9,213,807 · App. 14/018,234 · Granted Dec 15, 2015

Detection of code injection attacks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,213,807
App. No.
14/018,234
Granted
Dec 15, 2015
Kind
B2
Abstract

A method for detecting foreign code injected into a computer system including a processor and memory, the processor being configured to execute instructions stored in the memory, includes: detecting, on the computer system, an illegal instruction error; recording the illegal instruction error; determining whether a threshold condition is met; and generating an alert if the threshold condition is met.

Claims (48)

1. A method for detecting foreign code injected into a computer program executed by a heterogeneous computer system comprising a plurality of different processors each with different architecture and different native instruction set, and memory, the plurality of different processors being configured to execute instructions stored in the memory, the method comprising:

executing a first portion of the computer program by a first processor having a first architecture and a first instruction set;

executing a second portion of the computer program by a second processor having a second architecture and a second instruction set different than the first instruction set;

detecting, on the heterogeneous computer system, an illegal instruction error;

recording the illegal instruction error;

determining whether a threshold condition for an attack on the heterogeneous computer system is met based on patterns of multiple previous attacks clustered together and the number of different architectures; and

generating an alert if the threshold condition for the attack on the heterogeneous computer system is met, wherein the illegal instruction error is triggered by an instruction encoded in a third instruction set different from the first and second instruction sets.

2. The method of claim 1 , wherein the threshold condition further comprises exceeding a particular number of illegal instruction errors over a particular time period.

3. The method of claim 1 , wherein determining whether the threshold condition is met comprises detecting the patterns using a neural network.

4. The method of claim 1 , wherein the threshold condition comprises detecting the patterns using a Bayesian network.

5. The method of claim 1 , further comprising:

loading a plurality of instruction streams, each of the plurality of instruction streams being equivalent and being encoded in a different instruction set of a plurality of instruction sets;

executing, in a context, a first stream of the plurality of instruction streams;

stopping execution of the first stream at a first location of the first stream; and

executing, in the context, a second stream of the plurality of instruction streams at a second location of the second stream, the second location corresponding to the first location of the first stream,

wherein the first stream and the second stream are encoded in instruction sets different from the second instruction set.

6. The method of claim 1 , wherein generating the alert comprises sending an email message or a text message.

7. The method of claim 1 , further comprising shutting down the computer system when the threshold condition is met.

8. A computer system comprising a plurality of different processors each with different architecture and different native instruction set, and memory storing program instructions, the computer system being configured to execute instructions stored in the memory, the computer system being configured to:

execute a first portion of the computer program by a first processor having a first architecture and a first instruction set;

execute a second portion of the computer program by a second processor having a second architecture and a second instruction set different than the first instruction set;

detect an illegal instruction error;

record the illegal instruction error;

determine whether a threshold condition for an attack on the heterogeneous computer system is met based on patterns of multiple previous attacks clustered together and the number of different architectures; and

generate an alert if the threshold condition for the attack on the heterogeneous computer system is met, wherein the illegal instruction error is triggered by an instruction encoded in a third instruction set different from the first and second instruction sets.

9. The computer system of claim 8 , wherein the threshold condition further comprises exceeding a particular number of illegal instruction errors over a particular time period.

10. The computer system of claim 8 , wherein the computer system is configured to determine whether the threshold condition is met by detecting the patterns using a neural network.

11. The computer system of claim 8 , wherein the computer system is configured to determine whether the threshold condition is met by detecting the patterns using a Bayesian network.

12. The computer system of claim 8 , wherein the computer system is further configured to:

load a plurality of instruction streams, each of the plurality of instruction streams being equivalent and being encoded in a different instruction set of a plurality of instruction sets;

execute, in a context, a first stream of the plurality of instruction streams;

stop execution of the first stream at a first location of the first stream; and

execute, in the context, a second stream of the plurality of instruction streams at a second location of the second stream, the second location corresponding to the first location of the first stream,

wherein the first stream and the second stream are encoded in instruction sets different from the second instruction set.

13. The computer system of claim 8 , wherein the computer system is configured to generate the alert by sending an email message or a text message.

14. The computer system of claim 8 , wherein the computer system is further configured to shut down the computer system when the threshold condition is met.

15. A non-transitory computer readable medium embodying program instructions for execution by a heterogeneous computer system, the program instructions adapting the heterogeneous computer system for:

executing a first portion of the computer program by a first processor having a first architecture and a first instruction set;

executing a second portion of the computer program by a second processor having a second architecture and a second instruction set different than the first instruction set;

detecting, on the heterogeneous computer system, an illegal instruction error; recording the illegal instruction error;

determining whether a threshold condition for an attack on the heterogeneous computer system is met based on patterns of multiple previous attacks clustered together and the number of different architectures; and

generating an alert if the threshold condition for the attack on the heterogeneous computer system is met, wherein the illegal instruction error is triggered by an instruction encoded in a third instruction set different from the first and second instruction sets.

16. The non-transitory computer readable medium of claim 15 , wherein the program instructions further adapt the processing apparatus for:

loading a plurality of instruction streams, each of the plurality of instruction streams being equivalent and being encoded in a different instruction set of a plurality of instruction sets;

executing, in a context, a first stream of the plurality of instruction streams;

stopping execution of the first stream at a first location of the first stream; and

executing, in the context, a second stream of the plurality of instruction streams at a second location of the second stream, the second location corresponding to the first location of the first stream,

wherein the illegal instruction error is triggered by a program instruction encoded in a first instruction set, the first instruction set being different from the instruction sets of the first stream and the second stream.

Assignments (15)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
CHANGE OF NAME Recorded Mar 21, 2025
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: EVERFOX HOLDINGS LLC
Reel/Frame 070585/0524 →
PARTIAL PATENT RELEASE AND REASSIGNMENT AT REEL/FRAME 055052/0302 Recorded Oct 3, 2023
From: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: FORCEPOINT FEDERAL HOLDINGS LLC (F/K/A FORCEPOINT LLC)
Reel/Frame 065103/0147 →
SECURITY INTEREST Recorded Sep 29, 2023
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 065086/0822 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0309 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: FORCEPOINT FEDERAL LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0460 →
CHANGE OF NAME Recorded Feb 16, 2016
From: RAYTHEON CYBER PRODUCTS, LLC
To: FORCEPOINT FEDERAL LLC
Reel/Frame 037821/0818 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2015
From: VORSANGER, GREG
To: RAYTHEON BBN TECHNOLOGIES CORP.
Reel/Frame 036941/0127 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
CHANGE OF NAME Recorded Jun 2, 2015
From: RAYTHEON CYBER PRODUCTS, INC.
To: RAYTHEON CYBER PRODUCTS, LLC
Reel/Frame 035806/0367 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2015
From: RAYTHEON BBN TECHNOLOGIES CORP.
To: RAYTHEON CYBER PRODUCTS, INC.
Reel/Frame 035794/0226 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2013
From: MARTZ, ROBERT; MATTHEWS, DAVID; EDMISON, JOSHUA
To: RAYTHEON BBN TECHNOLOGIES, CORP.
Reel/Frame 031205/0777 →
CONFIRMATORY LICENSE Recorded Sep 6, 2013
From: RAYTHEON BBN TECHNOLOGIES CORPORATION
To: AFRL/RIJ
Reel/Frame 031171/0863 →