IP Library Granted Patent US 10,210,329
Granted Patent B1
US 10,210,329 · App. 14/871,987 · Granted Feb 19, 2019

Method to detect application execution hijacking using memory protection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,210,329
App. No.
14/871,987
Granted
Feb 19, 2019
Kind
B1
Abstract

According to one embodiment, a system comprising a dynamic analysis server comprising one or more virtual machines is disclosed, wherein the one or more virtual machines may be configured to execute certain event logic with respect to a loaded module. The virtual machines may be communicatively coupled to a virtual machine manager and a database; and rule-matching logic comprising detection logic, wherein the detection logic is configured to determine (1) whether an access source is attempting to access a protected region such as a page guarded area; and (2) determine whether the access source is from the heap. The system further comprises reporting logic that is configured to generate an alert so as to notify a user and/or network administrator of a probable application-execution hijacking attack.

Claims (43)

1. An electronic device, comprising:

one or more hardware processors; and

a non-transitory computer-readable storage medium communicatively coupled to the one or more hardware processors, the non-transitory computer-readable storage medium having stored thereon logic that, upon execution by the one or more hardware processors, performs operations comprising:

identifying a loaded module,

applying a protection mechanism to an element of the loaded module so as to establish a protected region, wherein the element of the loaded module is one of a base address of the loaded module, an import table of the loaded module or a process environment block of the loaded module,

determining whether an access source is attempting to access the protected region,

determining whether the access source is from the heap, and

determining the access source is malicious based on determining the access source is attempting to access the protected region and is from the heap.

2. The electronic device of claim 1 , wherein the execution by the one or more hardware processors performs operations further comprising generating an alert so as to notify a user or a network administrator of a probable application-execution hijacking attack.

3. The electronic device of claim 1 , wherein the execution by the one or more processors performs operations further comprising terminating the loaded module so as to prevent an application-execution hijacking attack.

4. The electronic device of claim 1 , wherein the execution by the one or more processors performs operations further comprising generating a log file.

5. The electronic device of claim 1 , wherein the loaded module includes executable code.

6. An electronic device, comprising:

one or more hardware processors; and

a non-transitory computer-readable storage medium communicatively coupled to the one or more hardware processors, the non-transitory computer-readable storage medium having stored thereon logic that, upon execution by the one or more hardware processors, performs operations comprising:

identifying a loaded module,

applying a protection mechanism to an import table of the loaded module so as to establish a protected region,

determining whether an access source is attempting to access the protected region,

determining whether the access source is from the heap,

determining whether the access source is from the loaded module and accessing its own import address table, and

determining the access source is malicious based on determining the access source is (i) attempting to access the protected region, (ii) from the heap, and (iii) accessing its own import address table.

7. The electronic device of claim 5 , wherein the loaded module comprises one or more dynamic-link libraries (DLLs) that provide a scripting environment to applications.

8. The electronic device of claim 6 , wherein the loaded module includes executable code.

9. A system comprising:

a dynamic analysis server comprising one or more hardware processors, a non-transitory computer-readable storage medium and one or more virtual machines that are configured to execute event logic with respect to a loaded module, wherein the one or more virtual machines are communicatively coupled to a virtual machine manager and a database;

rule-matching logic comprising detection logic configured to be executable by the one or more hardware processors to determine whether (1) an access source is attempting to access a protected region, and (2) the access source is from the heap; and

reporting logic comprising alert generating logic that is configured to generate an alert so as to notify a user or a network administrator of a probable application-execution hijacking attack.

10. The system of claim 7 , further comprising process handling logic that is configured to terminate a potentially malicious loaded module.

11. The system of claim 7 , wherein the detection logic is configured to determine whether a protected page is being accessed, and whether the access source is from the heap.

12. The system of claim 9 , wherein the detection logic is configured to determine whether the loaded module is accessing its own import table.

13. The system of claim 9 , wherein the loaded module includes executable code.

14. The system of claim 9 , wherein further comprising dynamic-link library (DLL)/kernel logic that modularizes a software program into separate components.

15. A system comprising:

a mobile device configured to execute a malware detection application thereon, the detection application comprising:

exploit detection logic configured to execute certain event logic with respect to a loaded module;

rule-matching logic comprising detection logic configured to determine whether an access source is attempting to access a protected region and determine whether the access source is from the heap;

reporting logic comprising alert generating logic that is configured to generate an alert; and

user interface logic that is configured to notify a user or a network administrator of a probable application-execution hijacking attack.

16. The system of claim 11 , wherein the exploit detection logic is configured to terminate the loaded module.

17. The system of claim 11 , wherein the exploit detection logic is configured to generate an alert.

18. The system of claim 15 , further comprising process handling logic that is configured to terminate a potentially malicious loaded module.

19. The system of claim 15 , wherein the loaded module includes executable code.

20. The system of claim 15 , wherein further comprising dynamic-link library (DLL)/kernel logic that modularizes a software program into separate components.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063287/0707 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063287/0702 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2015
From: MALIK, AMIT; PANDE, RAGHAV; JAIN, AAKASH
To: FIREEYE, INC.
Reel/Frame 036718/0685 →
Cited By (22)
US 12,200,006 US 12,200,013 US 12,223,060 US 12,223,337 US 12,248,563 US 12,273,367 US 12,278,834 US 12,282,564 US 12,335,297 US 12,348,485 US 12,348,561 US 12,353,563 US 12,363,145 US 12,388,865 US 12,425,437 US 12,445,458 US 12,445,481 US 12,462,016 US 12,481,765 US 12,587,555 US 12,639,438 US 12,647,433