IP Library Granted Patent US 9,374,390
Granted Patent B1
US 9,374,390 · App. 14/603,652 · Granted Jun 21, 2016

Policy-based whitelisting with system change management based on trust framework

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,374,390
App. No.
14/603,652
Granted
Jun 21, 2016
Kind
B1
Abstract

Techniques allow runtime extensions to a whitelist that locks down a computational system. For example, executable code is not only subject to whitelist checks that allow (or deny) its execution, but is also subject to checks that determine whether a whitelisted executable is itself trusted to introduce further executable code into the computational system in which it is allowed to run. In general, deletion and/or modification of instances of code that are already covered by the whitelist are also disallowed in accordance with a security policy. Accordingly, an executable that is trusted may be allowed to delete and/or modify code instances covered by the whitelist. In general, trust may be coded for a given code instance that seeks to introduce, remove or modify code.

Claims (53)

1. A method of managing a whitelist that at least partially governs operation of a computational system, the method comprising:

providing a computer readable encoding of the whitelist, wherein the whitelist identifies (i) instances of code that are allowed to execute on the computational system and (ii) trust attributes therefor, wherein at least one of the trust attributes indicates, for a trusted one of the code instances, that a further code instance introduced into the computational system based on execution of the trusted code instance is to be added to the whitelist and thereby allowed to execute;

responsive to execution of a first code instance that at least initiates introduction of an executable second code instance into the computational system, checking a whitelist entry that corresponds to the first code instance and, based thereon, extending the whitelist to allow execution of the second code instance only if the whitelist entry includes a trust attribute; and

executing on the computational system only those code instances allowed by the whitelist;

wherein relative to the first code instance and the second code instance, the extending the whitelist comprises adding an entry comprising:

a size of a file from which the second code instance may be loaded into memory and executed;

a name of the file or a path thereto; and

a hash, a digital signature, authentication code, checksum, fingerprint or other cryptographic digest usable to verify integrity of the file.

2. The method of claim 1 ,

wherein the whitelist identifies individual ones of the code instances and trust attributes therefor by correspondence with respective files in a file system.

3. The method of claim 1 , wherein relative to the first code instance, the whitelist encodes:

a size of a first file in a file-system from which the first code instance is loaded into memory and executed;

a name of the first file; and

a hash, a digital signature, authentication code, checksum, fingerprint or other cryptographic digest that verifies integrity of the first file.

4. The method of claim 3 , wherein relative to the first code instance, the whitelist further encodes:

a path to the first file, wherein the path is specified with or without wildcards.

5. The method of claim 1 , wherein relative to the first code instance, the whitelist comprises an entry including:

a full path to a first file, specified with or without wildcards.

6. The method of claim 3 , wherein the whitelist encodes one or more additional attributes selected from a set thereof that when individually set/cleared, direct a kernel resident security feature to:

allow/disallow read access to the first file;

allow/disallow overwriting of the first file;

allow/disallow loading of the first file into memory and execution thereof; and

allow/disallow deletion of the first file from the file-system.

7. The method of claim 3 ,

wherein existence of a whitelist entry corresponding to the first code instance constitutes an allow-type execution entry therefor.

8. The method of claim 3 ,

wherein attributes including the trust attribute are encoded independent of file-system permissions.

9. The method of claim 1 , further comprising:

interposing on file system operations and, as a condition precedent to execution of any particular code instance, determining that a corresponding allow-type entry appears in the whitelist.

10. The method of claim 9 , wherein the interposing on file system operations includes one or more of:

hooking file system calls;

hooking a function pointer table in an operating system kernel; and

interposing a file filter driver.

11. The method of claim 1 , further comprising:

maintaining in correspondence with call sequences of code executing on the computational system, a data structure that encodes for a given process, correspondence back to an operative entry of the whitelist.

12. The method of claim 11 , further comprising:

interposing on a write-type operation performed by either the first code instance or a third code instance executed based on a call sequence traceable to the first code instance; and

as a condition precedent to allowing the interposed upon write-type operation to introduce into the computational system an executable file loadable as the second code instance, checking to ensure that a corresponding trust attribute so allows.

13. The method of claim 11 ,

wherein the trust attribute conveys effective trust for changes to a third code instance executed based on a call sequence traceable to the first code instance if each code instance along the call sequence has a corresponding allow-type entry in the whitelist.

14. A system of selectively allowing and disallowing changes in a computational system, the system comprising:

memory;

a processor; and

a kernel-resident client, stored in the memory, that, responsive to code execution, by the processor, for a first code instance on an endpoint that seeks to modify a protected state of the endpoint, initiates a trusted change policy check of a whitelist for an allow-type entry that corresponds to the code execution, wherein the whitelist identifies trust attributes for instances of code that are allowed to execute on the computational system, and wherein at least one of the trust attributes indicates, for a trusted one of the code instances, that a further code instance introduced into the computational system based on execution of the trusted code instance is to be added to the whitelist and thereby allowed to execute,

wherein, if the allow-type entry includes a trust attribute, the kernel-resident client allows the code execution to proceed with the modification of the protected state and at least provisionally extending a current security policy that governs operation of the computational system to allow operation consistent with the modification, and wherein the kernel-resident client otherwise disallows the code execution by the processor and thereby blocks the modification,

wherein based on the allow-type entry including the trust attribute, the whitelist is extended to allow execution of a second code instance, wherein relative to the first code instance and the second code instance, the extending the whitelist comprises adding an entry comprising: (i) a size of a file from which the second code instance may be loaded into memory and executed, (ii) a name of the file or a path thereto, and (iii) a hash, a digital signature, authentication code, checksum, fingerprint or other cryptographic digest usable to verify integrity of the file.

15. The system of claim 14 , further comprising:

a security manager configured to receive an encoding of the at least provisionally-made extension for one or more of logging, review, approval and reversal.

16. The system of claim 14 ,

wherein the security manager is hosted on a secured computational system.

17. The system of claim 14 ,

wherein the security manager is configured as a network appliance, and

wherein the kernel-resident client is embodied as code installed to the endpoint from the network appliance.

Assignments (23)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2025
From: IVANTI SECURITY HOLDINGS LLC
To: IVANTI, INC.
Reel/Frame 071958/0203 →
2025-1 SECOND LIEN SECURITY AGREEMENT Recorded May 5, 2025
From: IVANTI SECURITY INTERMEDIATE HOLDINGS LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0498 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2025
From: IVANTI, INC.
To: IVANTI SECURITY HOLDINGS LLC
Reel/Frame 071180/0690 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
PARTIAL RELEASE OF SECURITY INTERESTS Recorded May 5, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; CHERWELL SOFTWARE, LLC
Reel/Frame 071176/0289 →
SECURITY INTEREST Recorded May 3, 2025
From: IVANTI SECURITY HOLDINGS LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0164 →
RELEASE OF SECURITY INTEREST Recorded May 2, 2025
From: ALTER DOMUS (US) LLC
To: IVANTI SECURITY HOLDINGS LLC
Reel/Frame 071162/0130 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41459/0436 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: HEAT SOFTWARE USA INC.
Reel/Frame 054560/0713 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41052/0735 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: HEAT SOFTWARE USA INC.
Reel/Frame 054560/0744 →
MERGER Recorded Jan 10, 2019
From: HEAT SOFTWARE USA INC.
To: IVANTI, INC.
Reel/Frame 047950/0296 →
RELEASE OF SECURITY INTERESTS IN PATENTS AT REEL/FRAME NO. 35111/0448 Recorded Jan 21, 2017
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: HEAT SOFTWARE USA INC., AS SUCCESSOR IN INTEREST TO LUMENSION SECURITY, INC.
Reel/Frame 041052/0802 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: HEAT SOFTWARE USA INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041052/0735 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: HEAT SOFTWARE USA INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041459/0436 →
MERGER AND CHANGE OF NAME Recorded Jan 18, 2017
From: LUMENSION SECURITY INC.; HEAT SOFTWARE USA INC.
To: HEAT SOFTWARE USA INC.
Reel/Frame 041010/0854 →
RELEASE OF SECURITY INTEREST Recorded Oct 25, 2016
From: CONSORTIUM FINANCE, LLC
To: NETMOTION WIRELESS HOLDINGS, INC.; NETMOTION WIRELESS, INC.; LUMENSION SECURITY, INC.
Reel/Frame 040479/0001 →
FIRST AMENDMENT TO PATENT SECURITY AGREEMENT Recorded Feb 28, 2015
From: LUMENSION SECURITY, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 035111/0448 →
FIRST AMENDMENT TO PATENT SECURITY AGREEMENT Recorded Feb 23, 2015
From: NETMOTION WIRELESS HOLDINGS, INC.; NETMOTION WIRELESS, INC.; LUMENSION SECURITY, INC.
To: CONSORTIUM FINANCE, LLC
Reel/Frame 035061/0615 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2015
From: CORETRACE CORPORATION
To: LUMENSION SECURITY, INC.
Reel/Frame 034858/0540 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2015
From: TEAL, DANIEL M.; MILLER, WESLEY G.; CASTAGNOLI, CHARISSE; JENNINGS, TONEY; SCHELL, TODD; TEAL, RICHARD S.
To: CORETRACE CORPORATION
Reel/Frame 034853/0183 →