IP Library Granted Patent US 9,767,283
Granted Patent B2
US 9,767,283 · App. 14/318,242 · Granted Sep 19, 2017

System and method to mitigate malicious calls

Inventors: Peter Szor (Santa Clara, CA); Rachit Mathur (Hillsboro, OR)
Assignee: McAfee, Inc.
G06F21/566
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,767,283
App. No.
14/318,242
Granted
Sep 19, 2017
Kind
B2
Abstract

Systems and methods are provided in example embodiments for mitigating malicious calls. The system can be configured to receive a function call, determine the location of a memory page that initiated the function call, determine if the memory page is associated with a trusted module, and block the function call if the memory page is not associated with the trusted module. In addition, the system can determine the return address for the function call and block the function call if the return address does not belong to the trusted module. Further, the system can determine a parameter for the function call, determine if the parameter is a known parameter used by the process that called the function, and block the function call if the parameter is not the known parameter used by the process that called the function.

Claims (49)

1. At least one non-transitory computer-readable medium comprising one or more instructions that, when executed by a processor, perform a method comprising:

receiving a function call from a security program, wherein the function call is an asynchronous procedure call;

determining a return address for the function call on an operating system stack above an address of the function call; and

pushing parameters on the operating system stack for a call for a dynamic link library to lead an operating system kernel back to restore a routine, if the return address does not belong to a trusted module.

2. The at least one non-transitory computer-readable medium of claim 1 , the method further comprising:

allowing the function call if the return address does belong to the trusted module.

3. The at least one non-transitory computer-readable medium of claim 2 , the method further comprising:

determining a location of a memory page that initiated the function call;

determining if the memory page is associated with the trusted module; and

blocking the function call if the memory page is not associated with the trusted module.

4. The at least one non-transitory computer-readable medium of claim 3 , the method further comprising:

allowing the function call if the memory page is associated with the trusted module.

5. The at least one non-transitory computer-readable medium of claim 1 , wherein the trusted module is part of the security program.

6. The at least one non-transitory computer-readable medium of claim 1 , the method further comprising:

determining whether the return address on the operating system stack points back to the security program.

7. The at least one non-transitory computer-readable medium of claim 1 , further comprising:

determining whether the return address is within a predetermined distance on the operating system stack from the function call.

8. The at least one non-transitory computer-readable medium of claim 1 , the method further comprising:

determining whether the operating system stack includes an address to an executable page that does not belong to an active process dynamic link library.

9. The at least one non-transitory computer-readable medium of claim 1 , wherein the parameters are pushed on the operating system stack with a security program interface module to prevent a termination of a process.

10. An apparatus, comprising:

a processor configured to

receive a function call from a security program, wherein the function call is an asynchronous procedure call;

determine if a memory page is associated with a trusted module by determining a return address for the function call on an operating system stack above an address of the function call; and

push parameters on the operating system stack for a call for a dynamic link library to lead an operating system kernel back to restore a routine, if the memory page is not associated with the trusted module.

11. The apparatus of claim 10 , wherein the function call is allowed if the memory page is associated with the trusted module.

12. The apparatus of claim 10 , wherein the processor is further configured to determine whether the return address on the operating system stack points back to the security program.

13. The apparatus of claim 10 , wherein the processor is further configured to determine whether the return address is within a predetermined distance on the operating system stack from the function call.

14. The apparatus of claim 10 , wherein the processor is further configured to determine whether the operating system stack includes an address to an executable page that does not belong to an active process dynamic link library.

15. The apparatus of claim 10 , wherein the parameters are pushed on the operating system stack with a security program interface module to prevent a termination of a process.

16. The apparatus of claim 10 , wherein the trusted module is part of the security program.

17. A method, comprising:

receiving an exit process function call from a process, wherein the exit process function call is an asynchronous procedure call;

determining a parameter for the exit process function call;

determining if the parameter is an exit code for the exit process function call used by the process, wherein the process identifies the exit code; and

blocking the exit process function call if the parameter is not the exit code.

18. The method of claim 17 , further comprising:

allowing the exit process function call if the parameter is the exit code.

19. The method of claim 17 , wherein the process is a security program.

20. A system for mitigating malicious calls, the system comprising:

a processor configured for

receiving a function call from a security program, wherein the function call is an asynchronous procedure call;

determining a return address for the function call on an operating system stack above an address of the function call; and

pushing parameters on the operating system stack for a call for a dynamic link library to lead an operating system kernel back to restore a routine, if the return address does not belong to a trusted module.

21. The system of claim 20 , wherein the processor is further configured for determining whether the return address on the operating system stack points back to the security program.

22. The system of claim 20 , wherein the processor is further configured for determining whether the return address is within a predetermined distance on the operating system stack from the function call.

23. The system of claim 20 , wherein the processor is further configured for determining whether the operating system stack includes an address to an executable page that does not belong to an active process dynamic link library.

24. The system of claim 20 , wherein the parameters are pushed on the operating system stack with a security program interface module to prevent a termination of a process.

25. The system of claim 20 , wherein the processor is further configured for allowing the function call if the return address does belong to the trusted module.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2016
From: SZOR, PETER; MATHUR, RACHIT
To: MCAFEE, INC.
Reel/Frame 040595/0440 →
Continuity (1)
Related Publication 20150379267A1 · Dec 31, 2015