IP Library Patent Application 15051461
Patent Application
App. No. 15/051,461

Integrity Assurance and Rebootless Updating During Runtime

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/051,461
Abstract

Techniques are described herein for, without rebooting a computing device, unloading at least a component of a kernel-mode component of the computing device and loading an updated version of the component of the kernel-mode component. The techniques may be performed by an integrity manager associated with the kernel-mode component. The integrity manager may also determine integrity of the kernel-mode component by causing the kernel-mode component to perform an action associated with a known reaction, determining whether the known reaction occurred, and in response, performing a remediation action or notifying a remote security service. Further, the integrity manager may determine whether any computing device lists include representations of components or connections associated with the kernel-mode component. The integrity manager may then remove the representations from the lists or remove the representations from responses to requests for contents of the computing device lists.

Claims (35)

1 .- 20 . (canceled)

21 . One or more computer storage media having stored thereon a plurality of executable instructions configured to program a computing device to perform operations comprising:

determining whether a computing device list includes a representation of a component or a connection associated with a kernel-mode component of the computing device; and

in response to the determining, performing one of:

removing the representation of the component or the connection from the computing device list, or

removing the representation of the component or the connection from a response to a request for contents of the computing device list.

22 . The one or more computer storage media of claim 21 , wherein the computing device list is a list of drivers, a list of network connections, a list of operating system hooks, a list of directories, or a list of registry keys.

23 . The one or more computer storage media of claim 21 , wherein the component is a driver, an operating system hook, a directory, or a registry key.

24 . The one or more computer storage media of claim 21 , wherein the operations further comprise intercepting the response to the request for contents of the computing device list.

25 . The one or more computer storage media of claim 21 , wherein the operations further comprise intercepting a request to open a directory associated with the kernel-mode component and responding that the directory does not exist or is not available.

26 . The one or more computer storage media of claim 21 , wherein the component is a component of the kernel-mode component, and the executable instructions configured to program the computing device to perform the determining, the removing the representation from the computing device list, or the removing the representation from the response are instructions of the kernel-mode component.

27 . The one or more computer storage media of claim 26 , wherein the executable instructions configured to program the computing device to perform the determining, the removing the representation from the computing device list, or the removing the representation from the response are instructions of an integrity manager of the kernel-mode component.

28 . A method implemented by a computing device, the method comprising:

determining whether a computing device list includes a representation of a component or a connection associated with a kernel-mode component of the computing device; and

in response to the determining, performing one of:

removing the representation of the component or the connection from the computing device list, or

removing the representation of the component or the connection from a response to a request for contents of the computing device list.

29 . The method of claim 28 , wherein the computing device list is a list of drivers, a list of network connections, a list of operating system hooks, a list of directories, or a list of registry keys.

30 . The method of claim 28 , wherein the component is a driver, an operating system hook, a directory, or a registry key.

31 . The method of claim 28 , further comprising intercepting the response to the request for contents of the computing device list.

32 . The method of claim 28 , further comprising intercepting a request to open a directory associated with the kernel-mode component and responding that the directory does not exist or is not available.

33 . The method of claim 28 , wherein the component is a component of the kernel-mode component, and the determining, the removing the representation from the computing device list, or the removing the representation from the response are performed by the kernel-mode component.

34 . The method of claim 33 , wherein the determining, the removing the representation from the computing device list, or the removing the representation from the response are performed by an integrity manager of the kernel-mode component.

35 . A computing device comprising:

a processor;

a kernel-mode component configured to be operated by the processor to perform operations including:

determining whether a computing device list includes a representation of a component or a connection associated with the kernel-mode component of the computing device; and

in response to the determining, performing one of:

removing the representation of the component or the connection from the computing device list, or

removing the representation of the component or the connection from a response to a request for contents of the computing device list.

36 . The computing device of claim 35 , wherein the computing device list is a list of drivers, a list of network connections, a list of operating system hooks, a list of directories, or a list of registry keys.

37 . The computing device of claim 35 , wherein the component is a driver, an operating system hook, a directory, or a registry key.

38 . The computing device of claim 35 , wherein the operations further include intercepting the response to the request for contents of the computing device list.

39 . The computing device of claim 35 , wherein the operations further include intercepting a request to open a directory associated with the kernel-mode component and responding that the directory does not exist or is not available.

40 . The computing device of claim 35 , wherein the kernel-mode component includes an integrity manager configured to perform the determining, the removing the representation from the computing device list, or the removing the representation from the response.

Assignments (3)
SECURITY INTEREST Recorded Apr 22, 2019
From: CROWDSTRIKE HOLDINGS, INC.; CROWDSTRIKE, INC.; CROWDSTRIKE SERVICES, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 048953/0205 →
SECURITY INTEREST Recorded Aug 15, 2017
From: CROWDSTRIKE, INC.
To: SILICON VALLEY BANK
Reel/Frame 043300/0283 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2016
From: IONESCU, ION-ALEXANDRU
To: CROWDSTRIKE, INC.
Reel/Frame 037804/0421 →