IP Library Granted Patent US 10,185,838
Granted Patent B1
US 10,185,838 · App. 15/899,666 · Granted Jan 22, 2019

Methods to impede common file/process hiding techniques

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,185,838
App. No.
15/899,666
Granted
Jan 22, 2019
Kind
B1
Abstract

A processor-based method to defeat file and process hiding techniques in a computing device is provided. The method includes generating one of a path permutation, a symlink, or an address, for a path to open or obtain status of a tool or function in a library in a mobile computing device and making an open or status call for the tool or function, using the one of the path permutation, symlink or address. The method includes avoiding a pattern match and blocking, by an injected library, of the open or status call, the avoiding being a result of making the open or status call using the path permutation, symlink or address.

Claims (39)

1. A method to defeat file and process hiding techniques in mobile computing devices, at least a portion of the method being performed by a mobile computing device comprising one or more processors, the method comprising:

determining a tool or function to be opened or to obtain status thereof, the tool or function being in a library and having a first file system path;

determining an obfuscated second file system path usable to open or obtain status of the tool or function in the library, the obfuscated second file system path including a path permutation of the first file system path having more directory level transitions than the first file system path; and

making an open call or a status call for the tool or function using the obfuscated second file system path, the use of the obfuscated second file system path avoiding pattern matching and blocking by an injected library of the mobile computing device.

2. The method of claim 1 , wherein the obfuscated second file system path has at least a portion that is randomly generated.

3. The method of claim 1 , wherein the using the obfuscated second file system path detects a file or a folder hidden by the pattern matching and blocking by the injected library.

4. The method of claim 1 , wherein a “.” character is included in the obfuscated second file system path to augment the first file system path for a current directory.

5. The method of claim 1 , wherein a “..” character string is included in the obfuscated second file system path to augment the first file system path for a parent directory.

6. The method of claim 1 , wherein the first file system path is a shortest path to the tool or function.

7. The method of claim 1 , wherein:

the injected library is configured to use the pattern match in function hooking; and

the avoiding of the pattern match avoids the function hooking.

8. A method to defeat file and process hiding techniques in mobile computing devices, at least a portion of the method being performed by a mobile computing device comprising one or more processors, the method comprising:

determining a tool or function to be opened or to obtain status thereof, the tool or function being in a library and having a first file system path;

creating a symlink that points to the tool or function specified by the first file system path;

determining an obfuscated second file system path usable to open or obtain status of the tool or function in the library, the obfuscated second file system path invoking the symlink and differing in content or syntax from the first file system path; and

making an open call or a status call for the tool or function using the obfuscated second file system path, the use of the obfuscated second file system path avoiding pattern matching and blocking by an injected library of the mobile computing device.

9. The method of claim 8 , wherein the obfuscated second file system path has at least a portion that is randomly generated.

10. The method of claim 8 , wherein the using the obfuscated second file system path detects a file or a folder hidden by the pattern matching and blocking by the injected library.

11. The method of claim 8 , wherein the first file system path is a shortest path to the tool or function.

12. The method of claim 8 , wherein:

the injected library is configured to use the pattern match in function hooking; and

the avoiding of the pattern match avoids the function hooking.

13. A method to defeat file and process hiding techniques in mobile computing devices, at least a portion of the method being performed by a mobile computing device comprising one or more processors, the method comprising:

determining a tool or function to be opened or to obtain status thereof, the tool or function being in a library and having a first file system path;

determining an obfuscated second file system path usable to open or obtain status of the tool or function in the library, the obfuscated second file system path differing in content or syntax from the first file system path and including an address offset of the tool or function, the address offset of the tool or function being identified by:

determining an address for a linker;

determining an offset of a library lookup tool, relative to the linker;

calling the library lookup tool via the address for the linker and the offset; and

determining an address of the tool or function, based on the calling the library lookup tool;

making an open call or a status call for the tool or function using the obfuscated second file system path, the use of the obfuscated second file system path avoiding pattern matching and blocking by an injected library of the mobile computing device.

14. The method of claim 13 , wherein the offset of a library lookup tool, relative to the linker is determined by parsing an executable and linkable format (ELF) file for the tool or function.

15. The method of claim 13 , wherein the offset of a library lookup tool, relative to the linker is determined by using a pre-calculated offset for the tool or function.

16. The method of claim 13 , wherein the obfuscated second file system path has at least a portion that is randomly generated.

17. The method of claim 13 , wherein the using the obfuscated second file system path detects a file or a folder hidden by the pattern matching and blocking by the injected library.

18. The method of claim 13 , wherein the first file system path is the shortest path to the tool or function.

19. The method of claim 13 , wherein:

the injected library is configured to use the pattern match in function hooking; and

the avoiding of the pattern match avoids the function hooking.

Assignments (6)
CHANGE OF NAME Recorded May 18, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 063697/0493 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Mar 5, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 052109/0186 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2018
From: EVANS, NATHAN; BENAMEUR, AZZEDINE; SHEN, YUN
To: SYMANTEC CORPORATION
Reel/Frame 044977/0099 →