IP Library Granted Patent US 10,121,010
Granted Patent B2
US 10,121,010 · App. 15/153,629 · Granted Nov 6, 2018

System and method for preventing execution of malicious instructions stored in memory and malicious threads within an operating system of a computing device

Inventors: Gabriel D. Landau (Glen Burnie, MD); Nicholas Eli Fritts (Annapolis, MD)
Assignee: Endgame, Inc.
G06F21/577G06F21/55G06F21/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,121,010
App. No.
15/153,629
Granted
Nov 6, 2018
Kind
B2
Abstract

In one embodiment, a malicious code prevention module identifies potentially malicious instructions in volatile memory of a computing device and replaces them with innocuous instructions. In another embodiment, the malicious code prevention module identifies a potentially malicious thread within an operating system and replaces the first instruction in the thread with a new instruction that terminates the thread. Malicious code prevention module prevents malicious code from inflicting any harm on the computing device and its contents.

Claims (19)

1. A method of preventing a program of instructions from being executed in a computer system comprising a processor, memory, and a non-volatile storage device, the method comprising:

loading the program of instructions into memory;

determining if the program of instructions is backed by a file stored in the non-volatile storage device and is executable by the processor; and

if the program of instructions is not backed by a file stored in the non-volatile storage device or is not executable, identifying the program of instructions as potentially malicious and replacing the program of instructions with one or more No Operation (NOP) instructions and shell code, thereby preventing execution of the potentially malicious program of instructions by the processor.

2. The method of claim 1 , wherein if the program of instructions is backed by a file stored in the non-volatile storage device and is executable, executing the program of instructions by the processor.

3. The method of claim 1 , wherein the determining step comprises obtaining attribute information from an operating system running on the processor.

4. The method of claim 1 , further comprising: executing the shell code by the processor to place the processor into a safe state.

5. The method of claim 2 , wherein the determining step comprises obtaining attribute information for the program of instructions from an operating system running on the processor.

6. The method of claim 2 , further comprising: executing the shell code by the processor to place the processor into a safe state.

7. A non-transitory computer-readable medium containing instructions for causing a processor to perform the following steps:

determine if a program of instructions in memory is backed by a file stored in the non-volatile storage device and is executable by the processor;

if the program of instructions is not backed by a file stored in the non-volatile storage device or is not executable, identify the program of instructions as potentially malicious and replace the program of instructions with one or more No Operation (NOP) instructions and shell code, thereby preventing execution of the potentially malicious program of instructions by the processor; and

if the program of instructions is backed by a file stored in the non-volatile storage device and is executable, allow the processor to execute the program of instructions.

8. A method of preventing a program of instructions from being executed in a computer system comprising a processor, memory, and a non-volatile storage device, the method comprising:

loading the program of instructions into memory;

determining if the program of instructions is malicious;

determining if the program of instructions is backed by a file stored in the non-volatile storage device; and

if the program of instructions is not backed by a file stored in the non-volatile storage device, identifying the program of instructions as potentially malicious and replacing the program of instructions with one or more No Operation (NOP) instructions and shell code, thereby preventing execution of the potentially malicious program of instructions by the processor.

9. The method of claim 8 , further comprising: replacing all of part of the file stored in the non-volatile storage device with one or more No Operation (NOP) instructions and shell code.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 17, 2026
From: ELASTICSEARCH, INC.
To: ELASTICSEARCH TECHNOLOGIES (US) INC.
Reel/Frame 073810/0013 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 17, 2026
From: ENDGAME SYSTEMS, INC.
To: ELASTICSEARCH, INC.
Reel/Frame 073810/0057 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 25, 2018
From: LANDAU, GABRIEL D.; FRITTS, NICHOLAS ELI
To: ENDGAME, INC.
Reel/Frame 046968/0863 →
Continuity (1)
Related Publication 20170329973A1 · Nov 16, 2017