IP Library Granted Patent US 10,083,296
Granted Patent B2
US 10,083,296 · App. 14/752,890 · Granted Sep 25, 2018

Detection of malicious thread suspension

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,083,296
App. No.
14/752,890
Granted
Sep 25, 2018
Kind
B2
Abstract

In an example, there is disclosed a computing apparatus having one or more logic elements providing a security agent operable for: detecting that a first process has launch a second process and placed the second process in a suspended state; detecting that the first process has modified or attempted to modify the second process; classifying the modification as potentially malicious; and taking a remedial action. There is also disclosed one or more computer-readable storage mediums having stored thereon executable instructions for providing the security agent, and a computer-executable method of providing the security agent.

Claims (33)

1. A computing apparatus, comprising:

a processor;

a memory; and

one or more logic elements comprising a security agent configured to:

first detect that a first process has launched a second process and placed the second process in a suspended state, comprising identifying a create-suspended flag, and further comprising detecting that no “resume” instruction has been issued for the process;

second detect that after placing the second process in the suspended state, the first process has modified or attempted to modify the second process, comprising detecting that the first process has modified an import address table;

classify the first process as potentially malicious, based at least in part on the first detecting in combination with the second detecting; and

take a remedial action.

2. The computing apparatus of claim 1 , wherein the security agent is further configured to classify the modification as non-malicious, and permitting the first process to execute.

3. The computing apparatus of claim 1 , wherein detecting that the first process has placed the second process in a suspended state comprises detecting that a number-of-threads counter has been set to zero.

4. The computing apparatus of claim 1 , wherein detecting that the first process has placed the second process in a suspended state comprises inserting operating system hooks.

5. The computing apparatus of claim 1 , wherein detecting that the first process has placed the second process in a suspended state comprises inserting application-level hooks.

6. The computing apparatus of claim 1 , wherein classifying the first process as potentially malicious comprises determining that the first process has overwritten an entry point of the second process.

7. The computing apparatus of claim 1 , wherein classifying the first process as potentially malicious comprises detecting that the first process has introduced a jump or branching instruction at or near an entry point of the second process.

8. The computing apparatus of claim 1 , wherein classifying the first process as potentially malicious comprises detecting that the first process has created a remote thread on the second process.

9. The computing apparatus of claim 1 , wherein classifying the first process as potentially malicious comprises providing an operating system or user-mode hook.

10. The computing apparatus of claim 1 , wherein classifying the first process as potentially malicious comprises detecting that the first process has launched a plurality of processes that together effect a modification to the second process.

11. One or more tangible, non-transitory computer-readable storage mediums having stored thereon executable instructions for providing a security engine configured to:

first detecting that a first process has launched a second process and placed the second process in a suspended state, comprising identifying a create-suspended flag, and further comprising detecting that no “resume” instruction has been issued for the process;

second detecting that after placing the second process in the suspended state, the first process has modified or attempted to modify the second process, comprising detecting that the first process has modified an import address table;

classifying the first process as potentially malicious, based at least in part on the first detecting in combination with the second detecting; and

taking a remedial action.

12. The one or more tangible, non-transitory computer-readable storage mediums of claim 11 , wherein detecting that the first process has placed the second process in a suspended state comprises detecting that a number-of-threads counter has been set to zero.

13. The one or more tangible, non-transitory computer-readable storage mediums of claim 11 , wherein detecting that the first process has placed the second process in a suspended state comprises inserting operating system hooks.

14. The one or more tangible, non-transitory computer-readable storage mediums of claim 11 , wherein detecting that the first process has placed the second process in a suspended state comprises inserting application-level hooks.

15. The one or more tangible, non-transitory computer-readable storage mediums of claim 11 , wherein classifying the first process as potentially malicious comprises determining that the first process has overwritten an entry point of the second process.

16. The one or more tangible, non-transitory computer-readable storage mediums of claim 11 , wherein classifying the first process as potentially malicious comprises detecting that the first process has introduced a jump or branching instruction at or near an entry point of the second process.

17. The one or more tangible, non-transitory computer-readable storage mediums of claim 11 , wherein classifying the first process as potentially malicious comprises detecting that the first process has created a remote thread on the second process.

18. A computer-executable method of providing a security agent, comprising:

first detecting that a first process has launched a second process and placed the second process in a suspended state, comprising identifying a create-suspended flag, and further comprising detecting that no “resume” instruction has been issued for the process;

second detecting that after placing the second process in the suspended state, the first process has modified or attempted to modify the second process, comprising detecting that the first process has modified an import address table;

classifying the first process as potentially malicious, based at least in part on the first detecting in combination with the second detecting; and

taking a remedial action.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2016
From: KAPOOR, ADITYA; SPURLOCK, JOEL R.; EDWARDS, JONATHAN L.
To: MCAFEE, INC.
Reel/Frame 037954/0782 →