IP Library Granted Patent US 9,467,465
Granted Patent B2
US 9,467,465 · App. 14/182,651 · Granted Oct 11, 2016

Systems and methods of risk based rules for application control

Inventors: Brad Hibbert (Carp, CA); Chris Silva (Laguna Beach, CA)
Assignee: BeyondTrust Software, Inc.
H04L63/1433G06F21/554G06F21/577H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,467,465
App. No.
14/182,651
Filed
Feb 18, 2014
Granted
Oct 11, 2016
Kind
B2
Art Unit
2438
USPC
726/1
Abstract

In various embodiments, an agent on a digital device may comprise a monitor module, an application identification module, a vulnerability module, a rules database, and a rule module. The monitor module may be configured to monitor a device for an instruction to execute a legitimate application. The application identification module may be configured to identify one or more attributes of the legitimate application. The vulnerability module may be configured to retrieve risk information based on the one or more attributes of the legitimate application. The risk information may be determined from known vulnerabilities of the legitimate application. The rules database may be for storing a rule associated with the risk information. The rule module may be configured to retrieve the rule from the rule database based on the risk information and to control the legitimate application based on the rule.

Claims (48)

1. An agent comprising:

a monitor module, executing on a computing device, configured to monitor the computing device for an instruction to execute a legitimate application on the computing device, the legitimate application comprising a non-malware application;

an application identification module configured to identify one or more attributes of the legitimate application;

a vulnerability module configured to retrieve risk information based on the one or more attributes of the legitimate application, the risk information determined from known vulnerabilities of the legitimate application, the risk information including a risk value associated with the legitimate application;

a rules database for storing a rule associated with the risk information; and

a rule module configured to retrieve the rule from the rules database based on the risk information and to control the legitimate application based on a comparison of the risk value and a predetermined threshold risk value defined by the rule.

2. The agent of claim 1 , wherein the rule module configured to control the legitimate application comprises blocking the legitimate application from executing.

3. The agent of claim 1 , wherein the rule module configured to control the legitimate application comprises allowing the legitimate application to execute.

4. The agent of claim 1 , wherein the rule module configured to control the legitimate application comprises allowing the legitimate application to execute but blocking some functionality of the legitimate application from executing.

5. The agent of claim 1 , wherein the monitor module configured to monitor the computing device for an instruction to execute the legitimate application comprises the monitor module intercepting instructions being provided to or from an operating system of the computing device.

6. The agent of claim 1 , wherein one of the one or more attributes is an application identifier.

7. The agent of claim 1 , wherein one of the one or more attributes is an application version identifier.

8. The agent of claim 1 , wherein the rule comprises an instruction to block all or part of execution of the legitimate application if the risk information indicates, at least in part, that a vulnerability associated with the legitimate application was publicly disclosed before a predetermined date.

9. The agent of claim 8 , wherein the predetermined date is calculated as occurring at a period of time before a current date.

10. The agent of claim 1 , wherein the rule comprises an instruction to block all or part of execution of the legitimate application if the risk information indicates, at least in part, that a public exploit of a vulnerability associated with the legitimate application exists.

11. The agent of claim 1 , wherein the rule comprises an instruction to block all or part of execution of the legitimate application if the risk information indicates, at least in part, that a vulnerability associated with the legitimate application was identified before a predetermined period of time.

12. The agent of claim 1 , wherein the rule is applicable to multiple different legitimate applications on the computing device.

13. The agent of claim 1 , wherein the rule module is configured to retrieve a plurality of rules from the rule database, each of the plurality of rules associated with the risk information.

14. The agent of claim 13 , wherein the rule module configured to control the legitimate application based on the comparison of the risk value and the predetermined threshold risk value defined by the rule comprises controlling the legitimate application based on the comparison of the risk value and the predetermined threshold risk value defined by a strictest rule of the plurality of rules.

15. The agent of claim 1 , wherein the risk information comprises a risk value and the rule comprises instructions regarding control of the legitimate application based on the risk value.

16. A method comprising:

monitoring, via a processor, a computing device for an instruction to execute a legitimate application on the computing device, the legitimate application comprising a non-malware application;

identifying one or more attributes of the legitimate application;

retrieving risk information based on the one or more attributes of the legitimate application, the risk information determined from known vulnerabilities of the legitimate application, the risk information including a risk value associated with the legitimate application;

storing a rule associated with the risk information;

retrieving the rule from the rule database based on the risk information; and

controlling the legitimate application based on a comparison of the risk value and a predetermined threshold risk value defined by the rule.

17. The method of claim 16 , wherein controlling the legitimate application comprises blocking the legitimate application from executing.

18. The method of claim 16 , wherein the controlling the legitimate application comprises allowing the legitimate application to execute.

19. The method of claim 16 , wherein the controlling the legitimate application rule comprises allowing the legitimate application to execute but blocking some functionality of the legitimate application from executing.

20. The method of claim 16 , wherein the monitoring the device for an instruction to execute the legitimate application comprises intercepting instructions being provided to or from an operating system of the computing device.

21. The method of claim 16 , wherein one of the one or more attributes is an application identifier.

22. The method of claim 16 , wherein one of the one or more attributes is an application version identifier.

23. The method of claim 16 , wherein the rule comprises an instruction to block all or part of execution of the legitimate application if the risk information indicates, at least in part, that a vulnerability associated with the legitimate application was publicly disclosed before a predetermined date.

24. The method of claim 23 , wherein the predetermined date is calculated as occurring at a period of time before a current date.

25. The method of claim 16 , wherein the rule comprises an instruction to block all or part of execution of the legitimate application if the risk information indicates, at least in part, that a public exploit of a vulnerability associated with the legitimate application exists.

26. The method of claim 16 , wherein the rule comprises an instruction to block all or part of execution of the legitimate application if the risk information indicates, at least in part, that a vulnerability associated with the legitimate application was identified before a predetermined period of time.

27. The method of claim 16 , wherein the rule is applicable to multiple different legitimate applications on the computing device.

28. The method of claim 16 , wherein retrieving the rule comprises retrieving a plurality of rules from the rule database, each of the plurality of rules associated with the risk information.

29. The method of claim 28 , wherein controlling the legitimate application based on the comparison of the risk value and the predetermined threshold risk value defined by the rule comprises controlling the legitimate application based on the comparison of the risk value and the predetermined threshold risk value defined by a strictest rule of the plurality of rules.

30. The method of claim 16 , wherein the risk information comprises a risk value and the rule comprises instructions regarding control of the legitimate application based on the risk value.

31. A non-transitory computer readable medium comprising instructions executable by a processor to perform a method, the method comprising:

monitoring a computing device for an instruction to execute a legitimate application on the computing device, the legitimate application comprising a non-malware application;

identifying one or more attributes of the legitimate application;

retrieving risk information based on the one or more attributes of the legitimate application, the risk information determined from known vulnerabilities of the legitimate application, the risk information including a risk value associated with the legitimate application;

storing a rule associated with the risk information;

retrieving the rule from the rule database based on the risk information; and

controlling the legitimate application based on a comparison of the risk value and a predetermined threshold risk value defined by the rule.

Assignments (12)
MERGER Recorded Dec 5, 2023
From: BEYONDTRUST SOFTWARE, INC.
To: BEYONDTRUST CORPORATION
Reel/Frame 065764/0741 →
RELEASE OF SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 28, 2023
From: JEFFERIES FINANCE LLC,
To: BEYONDTRUST SOFTWARE, INC.
Reel/Frame 065697/0345 →
RELEASE OF FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 28, 2023
From: JEFFERIES FINANCE LLC
To: BEYONDTRUST SOFTWARE, INC.
Reel/Frame 065696/0798 →
SECURITY INTEREST Recorded Nov 28, 2023
From: BEYONDTRUST CORPORATION
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 065682/0447 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 4, 2018
From: BEYONDTRUST SOFTWARE, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 047195/0252 →
RELEASE OF SECURITY INTEREST UNDER REEL/FRAME NO. 044496/0009 Recorded Oct 3, 2018
From: ARES CAPITAL CORPORATION
To: BEYONDTRUST SOFTWARE, INC.
Reel/Frame 047189/0516 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 3, 2018
From: BEYONDTRUST SOFTWARE, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 047190/0238 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 033824/0803 Recorded Nov 21, 2017
From: OAKTREE FUND ADMINISTRATION, LLC (AS SUCCESSOR TO FIFTH STREET MANAGEMENT LLC)
To: BEYONDTRUST, INC.
Reel/Frame 044495/0927 →
PATENT SECURITY AGREEMENT Recorded Nov 21, 2017
From: BEYONDTRUST SOFTWARE, INC.
To: ARES CAPITAL CORPORATION
Reel/Frame 044496/0009 →
ASSIGNMENT OF PATENT SECURITY AGREEMENT Recorded Oct 20, 2017
From: FIFTH STREET MANAGEMENT LLC
To: OAKTREE FUND ADMINISTRATION, LLC
Reel/Frame 044242/0538 →
PATENT SECURITY AGREEMENT Recorded Sep 25, 2014
From: BEYONDTRUST, INC.
To: FIFTH STREET MANAGEMENT LLC
Reel/Frame 033824/0803 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 25, 2014
From: HIBBERT, BRAD; SILVA, CHRIS
To: BEYONDTRUST SOFTWARE, INC.
Reel/Frame 033244/0435 →
Continuity (3)
Continuation In Part 14156375 · Jan 15, 2014
Provisional Application 61768809 · Feb 25, 2013
Related Publication 20140245376A1 · Aug 28, 2014