IP Library Granted Patent US 10,885,212
Granted Patent B2
US 10,885,212 · App. 15/795,952 · Granted Jan 5, 2021

Secure management of process properties

Inventor: Richard S. Teal (Media, PA)
Assignee: Sophos Limited
G06F21/606G06F12/0813G06F21/44G06F21/50G06F21/51G06F21/54G06F21/55G06F21/554G06F21/57G06F21/602H04L9/0891H04L9/321H04L9/3247H04L9/3268H04L43/028H04L43/045H04L43/062H04L47/2475H04L63/02H04L63/0218H04L63/0227H04L63/0236H04L63/0263H04L63/14H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/168H04L63/20H04L63/205G06F2212/1052G06F2212/60G06F2212/62H04L9/30H04L43/026H04L43/10H04L63/145H04L67/2842
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,885,212
App. No.
15/795,952
Filed
Oct 27, 2017
Granted
Jan 5, 2021
Kind
B2
Examiner
ZEE, EDWARD
Art Unit
2435
USPC
726/7
Abstract

An endpoint has a tamper protection cache that identifies protected computing objects, along with a process cache that stores information for processes executing on the endpoint. By securing the tamper protection cache with reference to a trust authority external to the endpoint, or the operating system for the endpoint, computing objects listed in the tamper protection cache can be protected against unauthorized modifications from malware or other malicious or otherwise potentially unsafe code.

Claims (34)

1. A computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on an endpoint, performs the steps of:

storing a process cache in a kernel space of an operating system on the endpoint, the endpoint having a memory that includes the kernel space and a user space and the process cache storing at least one property for a first process executing in the user space;

storing a tamper protection cache in the kernel space, the tamper protection cache identifying one or more protected computing objects on the endpoint including the first process, wherein a record of the first process in the tamper protection cache is cryptographically secured with reference to a trust authority external to the operating system;

monitoring changes to the process cache with a kernel driver;

detecting a requested change from a second process executing on the endpoint to the at least one property of the first process with the kernel driver; and

conditionally approving the requested change from the kernel driver only when the second process is included in the one or more protected computing objects identified in the tamper protection cache.

2. A method for managing properties of processes on an endpoint, the method comprising:

storing a process cache in a kernel space of an operating system on the endpoint, the endpoint having a memory that includes the kernel space and a user space and the process cache storing at least one property for a first process executing in the user space;

storing a tamper protection cache in the kernel space, the tamper protection cache identifying one or more protected computing objects on the endpoint, wherein a record of the first process in the tamper protection cache is cryptographically secured with reference to a trust authority external to the operating system;

monitoring changes to the process cache with a kernel driver;

detecting a requested change from a second process executing on the endpoint to the at least one property of the first process with the kernel driver; and

conditionally approving the requested change from the kernel driver based on a security rule and the tamper protection cache.

3. The method of claim 2 wherein the first process is a software firewall executing on the endpoint.

4. The method of claim 2 wherein conditionally approving the requested change includes reversing the requested change after the requested change is entered into the process cache.

5. The method of claim 2 wherein conditionally approving the requested change includes approving the requested change when the second process is identified as one of the one or more protected computing objects in the tamper protection cache.

6. The method of claim 2 wherein conditionally approving the requested change includes approving the requested change when neither the first process nor the second process is identified as one of the one or more protected computing objects in the tamper protection cache.

7. The method of claim 2 wherein conditionally approving the requested change includes, when the first process is identified as one of the protected computing objects in the tamper protection cache, approving the requested change only when the second process is also identified as one of the one or more protected computing objects in the tamper protection cache.

8. The method of claim 2 wherein the requested change includes a change to a registry key associated with the first process.

9. The method of claim 8 wherein the registry key is identified as one of the one or more protected computing objects in the tamper protection cache.

10. The method of claim 2 wherein the first process executes from a directory location identified as one of the one or more protected computing objects in the tamper protection cache.

11. The method of claim 2 wherein the tamper protection cache is secured by a trust authority external to the operating system.

12. The method of claim 2 wherein the tamper protection cache is secured with a digital signature from a remote trust authority.

13. The method of claim 2 wherein the requested change includes a change in at least one of process privileges or a user for the first process.

14. A system comprising:

an endpoint having a memory and an operating system that organizes the memory into a user space and a kernel space;

a process cache stored in the kernel space of the operating system, the process cache storing at least one property for a first process executing in the user space;

a tamper protection cache stored in the kernel space of the operating system, the tamper protection cache identifying one or more protected computing objects on the endpoint, wherein a record of the first process in the tamper protection cache is cryptographically secured with reference to a trust authority external to the operating system; and

a kernel driver in the kernel space of the operating system, the kernel driver configured to monitor changes to the process cache, to detect a requested change by a second process executing on the endpoint to the at least one property of the first process, and to conditionally approve the requested change from the kernel driver based on a security rule and the tamper protection cache.

15. The system of claim 14 wherein the first process is a software firewall executing on the endpoint.

16. The system of claim 14 wherein the kernel driver is configured to undo an unapproved change by reversing the requested change after the requested change is entered into the process cache.

17. The system of claim 14 wherein the kernel driver is configured to conditionally approve the requested change by approving the requested change only when the second process is identified as one of the one or more protected computing objects in the tamper protection cache.

18. The system of claim 14 wherein the kernel driver is configured to conditionally approve the requested change by approving the requested change when neither the first process nor the second process is identified as one of the one or more protected computing objects in the tamper protection cache.

19. The system of claim 14 wherein the kernel driver is configured to conditionally approve the requested change when the first process is identified as one of the one or more protected computing objects in the tamper protection cache by approving the requested change only when the second process is also identified as one of the one or more protected computing objects in the tamper protection cache.

20. The system of claim 14 wherein the tamper protection cache is secured by a trust authority external to the operating system.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2017
From: TEAL, RICHARD S.
To: SOPHOS LIMITED
Reel/Frame 044151/0933 →
Continuity (4)
Provisional Application 62557703 · Sep 12, 2017
Provisional Application 62571759 · Oct 12, 2017
Provisional Application 62572548 · Oct 15, 2017
Related Publication 20190080078A1 · Mar 14, 2019