IP Library Granted Patent US 11,030,302
Granted Patent B2
US 11,030,302 · App. 16/108,579 · Granted Jun 8, 2021

Restricting access to application programming interfaces (APIs)

Inventors: Andrew L. Sandoval (San Antonio, TX); John R. Shaw, II (Broomfield, CO)
Assignee: Webroot Inc.
G06F21/51G06F9/54G06F21/52G06F21/629
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,030,302
App. No.
16/108,579
Granted
Jun 8, 2021
Kind
B2
Abstract

Examples of the present disclosure describe systems and methods for restricting access to application programming interfaces (APIs). For example, when a process calls an API, the API call may be intercepted by a security system for evaluation of its trustfulness before the API is allowed to run. Upon intercepting an API call, the process calling the API may be evaluated to determine if the process is known to the security system, such that known processes that are untrusted may be blocked from calling the API. Further, when the security system cannot identify the process calling the API, the security service may evaluate a call stack associated with the call operation to determine if attributes of the call operation are known to the security system. If the call operation is known to the security system as untrusted, the call operation may be blocked from calling the API.

Claims (56)

1. A system comprising:

at least one processor; and

memory storing instructions that, when executed by the at least one processor, causes the system to perform a set of operation, the set of operations comprising:

monitoring at least one application programming interface (API) associated with performing one or more file finding functions;

intercepting a call operation directed to the at least one API, wherein the call operation is associated with a process attempting to perform at least one of the one or more file finding functions;

determining a trust level for the process; wherein determining the trust level for the process comprises:

accessing a process data store to compare one or more attributes of the process to information for a set of known processes to determine whether the process is an unknown process;

accessing a call operation data store to compare one or more attributes of the call operation to information for a set of known call operation attributes to determine whether the call operation is untrusted; and

determining the trust level for the process based at least in part on the determination whether the process is an unknown process and the determination whether the call operation is untrusted;

evaluating the determined trust level to determine whether the process is trusted or untrusted;

based on determining the process is untrusted, presenting a prompt to a user to allow the call operation;

responsive to a user indication to allow the call operation, allowing the call operation; and

based on determining the process is untrusted and absent a user indication to allow the call operation, blocking the call operation directed to the at least one API from performing the at least one of the one or more file finding functions.

2. The system of claim 1 , wherein the set of operations further comprises:

in response to receiving a user indication at the displayed prompt to allow the call operation, adding the process to a set of known processes in a process data store.

3. The system of claim 1 , wherein the set of operations further comprises:

in response to receiving a user indication at the displayed prompt to deny the call operation, terminating the process.

4. The system of claim 1 , wherein the prompt includes information relating to the at least one of the one or more file finding functions of the API.

5. The system of claim 1 , wherein intercepting the call operation comprises analyzing a call stack associated with the process for an operation having a wildcard character.

6. A method of restricting use of an application programming interface (API) associated with performing one or more file finding functions, the method comprising:

receiving a call operation directed to an API associated with performing one or more file finding functions, wherein the call operation is associated with a process;

performing an evaluation of the process based on the call operation, wherein the evaluation comprises at least one of:

comparing one or more attributes of the process to a set of known processes; and

comparing one or more attributes of the call operation to a set of known call operations;

determining, based at least in part on the evaluation, a trust level for the process, wherein determining the trust level for the process comprises:

accessing a process data store to compare one or more attributes of the process to information for a set of known processes to determine whether the process is an unknown process;

accessing a call operation data store to compare one or more attributes of the call operation to information for a set of known call operation attributes to determine whether the call operation is untrusted; and

determining the trust level for the process based at least in part on the determination whether the process is an unknown process and the determination whether the call operation is untrusted;

evaluating the determined trust level to determine whether the process is trusted or untrusted;

based on determining the process is untrusted, presenting a prompt to a user to allow the call operation;

responsive to a user indication to allow the call operation, allowing the call operation; and

based on determining that the process is untrusted and absent a user indication to allow the call operation, blocking the call operation directed to the API from performing at least one of the one or more file finding functions.

7. The method of claim 6 , wherein, in response to allowing the call operation based on a user indication to allow the call operation, the method further comprises at least one action selected from the group consisting of:

allowing the call operation and adding the process to the set of known processes; and

allowing the call operation only once.

8. The method of claim 6 , wherein, in response to blocking the call operation, the method further comprises:

capturing information associated with the process; and

reporting the process back to a security service.

9. The method of claim 6 , wherein the API is associated with a user-mode of the operating system.

10. A method of restricting use of at least one application programming interface (API), the method comprising:

monitoring at least one API associated with performing one or more file finding functions;

intercepting a call operation directed to the at least one API, wherein the call operation is associated with a process attempting to perform at least one of the one or more file finding functions;

determining a trust level for the process, wherein determining the trust level for the process comprises:

accessing a process data store to compare one or more attributes of the process to information for a set of known processes to determine whether the process is an unknown process;

accessing a call operation process data store to compare one or more attributes of the call operation to information for a set of known call operation attributes to determine whether the call operation is untrusted; and

determining the trust level for the process based at least in part on the determination whether the process is an unknown process and the determination whether the call operation is untrusted;

evaluating the determined trust level to determine whether the process is trusted or untrusted;

based on determining the process is untrusted, presenting a prompt to a user to allow the call operation;

responsive to a user indication to allow the call operation, allowing the call operation; and

based on determining the process is untrusted and absent a user indication to allow the call operation, blocking the call operation directed to the at least one API from performing the at least one of the one or more file finding functions.

11. The method of claim 10 , wherein the method further comprises:

in response to receiving a user indication at the displayed prompt to allow the call operation, adding the process to a set of known processes in a process data store.

12. The method of claim 10 , wherein the method further comprises:

in response to receiving a user indication at the displayed prompt to deny the call operation, terminating the process.

13. The method of claim 10 , wherein the prompt includes information relating to the at least one of the one or more file finding functions of the API.

14. The method of claim 10 , wherein intercepting the call operation comprises analyzing a call stack associated with the process for an operation having a wildcard character.

Assignments (7)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
RELEASE OF SECURITY INTEREST IN PATENT RIGHTS RECORDED AT R/F 048723/0612 Recorded Dec 26, 2019
From: BARCLAYS BANK PLC, AS COLLATERAL AGENT
To: WEBROOT INC.
Reel/Frame 051418/0714 →
SECURITY INTEREST Recorded Mar 28, 2019
From: WEBROOT INC.
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 048723/0612 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NAME OF ASSIGNOR SHAW, JOHN R. PREVIOUSLY RECORDED ON REEL 046661 FRAME 0798. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT OF ASSIGNORS INTEREST. Recorded Oct 1, 2018
From: SANDOVAL, ANDREW L.; SHAW, JOHN R., II
To: WEBROOT INC.
Reel/Frame 047171/0043 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2018
From: SANDOVAL, ANDREW L.; SHAW, JOHN R.
To: WEBROOT INC.
Reel/Frame 046661/0798 →
Continuity (2)
Provisional Application 62656722 · Apr 12, 2018
Related Publication 20190318079A1 · Oct 17, 2019