IP Library Granted Patent US 10,853,491
Granted Patent B2
US 10,853,491 · App. 16/007,507 · Granted Dec 1, 2020

Security agent

Inventors: David F. Diehl (Minneapolis, MN); Dmitri Alperovitch (Gaithersburg, MD); Ion-Alexandru Ionescu (Seattle, WA); George Robert Kurtz (Ladera Ranch, CA)
Assignee: CrowdStrike, Inc.
G06F21/566G06F9/46G06F21/554G06F21/56G06F21/567G06F21/568G06N5/04H04L41/0803H04L63/0245H04L63/1441G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,853,491
App. No.
16/007,507
Granted
Dec 1, 2020
Kind
B2
Abstract

A security agent is described herein. The security agent is configured to observe events, filter the observed events using configurable filters, route the filtered events to one or more event consumers, and utilize the one or more event consumers to take action based at least on one of the filtered events. In some implementations, the security agent detects a first action associated with malicious code, gathers data about the malicious code, and in response to detecting subsequent action(s) of the malicious code, performs a preventative action. The security agent may also deceive an adversary associated with malicious code. Further, the security agent may utilize a model representing chains of execution activities and may take action based on those chains of execution activities.

Claims (40)

1. A computing system, comprising:

one or more processors;

a memory configured to store a model associated with a kernel-level security agent, and computer-executable instructions associated with the kernel-level security agent that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

loading the kernel-level security agent before loading an operating system of the computing system;

observing, by the kernel-level security agent, execution activities of at least two processes executing on the computing system;

storing, by the kernel-level security agent, first data associated with a first execution activity of the execution activities in the model;

storing, by the kernel-level security agent, second data associated with a second execution activity of the execution activities in the model, wherein the model represents at least a first chain of execution activities; and

taking, by the kernel-level security agent, action based at least in part on the first chain of execution activities.

2. The computing system of claim 1 , wherein the first chain of execution activities represents a genealogy of at least one of the at least two processes.

3. The computing system of claim 1 , wherein the taking the action comprises halting or deceiving a process of the at least two processes, the process being associated with malicious activity.

4. The computing system of claim 1 , wherein the operations further comprise providing, by the kernel-level security agent, one or more of the first data or the second data to a remote security system.

5. The computing system of claim 4 , wherein the operations further comprise receiving, by the kernel-level security agent in response to providing the one or more of the first data or the second data to the remote security system, instructions associated with the action or a configuration update for configuring the kernel-level security agent.

6. The computing system of claim 5 , wherein the configuration update comprises a configurable filter, and the operations further comprise

detecting, by the kernel-level security agent, a subsequent action associated with malicious code, based at least in part on the configurable filter.

7. The computing system of claim 1 , wherein the kernel-level security agent observes the execution activities of the at least two processes based on one or more of hooks or filter drivers of the operating system.

8. The computing system of claim 1 , wherein the kernel-level security agent observes the execution activities at least in part by loading user mode collectors configured to observe user mode events associated with one or more of the at least two processes.

9. The computing system of claim 8 , wherein the kernel-level security agent filters the user mode events based on a configurable filter.

10. A computer-implemented method, comprising:

loading a kernel-level security agent on a computing system, prior to loading an operating system of the computing system;

observing, by the kernel-level security agent, execution activities of at least two processes executing on the computing system;

storing, by the kernel-level security agent, first data associated with a first execution activity of the execution activities in a model of the kernel-level security agent;

storing, by the kernel-level security agent, second data associated with a second execution activity of the execution activities in the model, wherein the model represents at least a first chain of execution activities; and

taking, by the kernel-level security agent, action based at least in part on the first chain of execution activities.

11. The computer-implemented method of claim 10 , wherein the first chain of execution activities represents a genealogy of at least one of the at least two processes.

12. The computer-implemented method of claim 10 , wherein the taking the action comprises halting or deceiving a process of the at least two processes, the process being associated with malicious activity.

13. The computer-implemented method of claim 10 , further comprising providing, by the kernel-level security agent, one or more of the first data or the second data to a remote security system.

14. The computer-implemented method of claim 10 , wherein the kernel-level security agent observes the execution activities of the at least two processes based on one or more of hooks or filter drivers of the operating system.

15. The computer-implemented method of claim 10 , wherein the kernel-level security agent observes the execution activities at least in part by loading user mode collectors configured to observe user mode events associated with one or more of the at least two processes.

16. One or more non-transitory computer-readable media storing computer-executable instructions associated with a kernel-level security agent that, when executed by one or more processors of a computing system, cause the one or more processors to perform operations comprising:

loading the kernel-level security agent, prior to loading an operating system of the computing system;

observing, by the kernel-level security agent, execution activities of at least two processes executing on the computing system;

storing, by the kernel-level security agent, first data associated with a first execution activity of the execution activities in a model of the kernel-level security agent;

storing, by the kernel-level security agent, second data associated with a second execution activity of the execution activities in the model, wherein the model represents at least a first chain of execution activities; and

taking, by the kernel-level security agent, action based at least in part on the first chain of execution activities.

17. The one or more non-transitory computer-readable media of claim 16 , wherein the first chain of execution activities represents a genealogy of at least one of the at least two processes.

18. The one or more non-transitory computer-readable media of claim 16 , wherein the taking the action comprises halting or deceiving a process of the at least two processes, the process being associated with malicious activity.

19. The one or more non-transitory computer-readable media of claim 16 , wherein the operations further comprise providing, by the kernel-level security agent, one or more of the first data or the second data to a remote security system.

20. The one or more non-transitory computer-readable media of claim 16 , wherein the kernel-level security agent observes the execution activities of the at least two processes based on at least one of:

one or more of hooks or filter drivers of the operating system, or

user mode collectors configured to observe user mode events associated with one or more of the at least two processes.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Jan 6, 2026
From: FIRST-CITIZENS BANK & TRUST COMPANY
To: CROWDSTRIKE HOLDINGS, INC.; CROWDSTRIKE, INC.
Reel/Frame 074202/0710 →
PATENT SECURITY AGREEMENT Recorded Jan 5, 2021
From: CROWDSTRIKE HOLDINGS, INC.; CROWDSTRIKE, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 054899/0848 →
SECURITY INTEREST Recorded Apr 22, 2019
From: CROWDSTRIKE HOLDINGS, INC.; CROWDSTRIKE, INC.; CROWDSTRIKE SERVICES, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 048953/0205 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2018
From: DIEHL, DAVID F.; ALPEROVITCH, DMITRI; IONESCU, ION-ALEXANDRU; KURTZ, GEORGE ROBERT
To: CROWDSTRIKE, INC.
Reel/Frame 046848/0059 →
Continuity (4)
Continuation 15393797 · Dec 29, 2016
Continuation 14140323 · Dec 24, 2013
Division 13492672 · Jun 8, 2012
Related Publication 20190138723A1 · May 9, 2019
Cited By (2)
US 12,499,211 US 12,587,564