IP Library Granted Patent US 11,416,612
Granted Patent B2
US 11,416,612 · App. 16/354,612 · Granted Aug 16, 2022

Protecting against malware code injections in trusted processes

Inventors: Vladimir Strogov (Moscow, RU); Serguei Beloussov (Costa del Sol, SG); Alexey Dod (Moscow, RU); Valery Chernyakovsky (Moscow, RU); Anatoly Stupak (Moscow, RU); Sergey Ulasen (Moscow, RU); Nikolay Grebennikov (Moscow, RU); Vyacheslav Levchenko (Moscow, RU); Stanislav Protasov (Moscow, RU)
Assignee: Acronis International GmbH
G06F21/566G06F21/52G06F21/568G06N20/00G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,416,612
App. No.
16/354,612
Granted
Aug 16, 2022
Kind
B2
Abstract

Disclosed are systems and methods for detecting malicious applications. The described techniques detect a first process has been launched on a computing device, and monitor at least one thread associated with the first process using one or more control points of the first process. An execution stack associated with the one or more control points of the first process is received from the first process. In response to detecting activity on the one or more control points of the first process, an indication that the execution of the first process is malicious is generated by applying a machine learning classifier to the received execution stack associated with the one or more control points of the first process.

Claims (32)

1. A computer-implemented method for detecting a malicious application, comprising:

detecting a first process has been launched on a computing device;

monitoring at least one thread associated with the first process using one or more control points of the first process;

receiving from the first process an execution stack associated with the one or more control points of the first process; and

responsive to detecting activity on the one or more control points of the first process, wherein the one or more control points are associated with a system call to create a remote thread that runs in a virtual address space of a second process, which is a shared-service process configured to import third-party processes to be embedded in the shared-service process as separate threads, generating an indication that the execution of the first process is malicious by applying a machine learning classifier to the received execution stack associated with the one or more control points of the first process.

2. The method of claim 1 , wherein the monitoring the at least one thread associated with the first process is performed using call stack trace monitoring.

3. The method of claim 1 , wherein the detecting the first process has launched and the monitoring the at least one thread associated with the first process is performed by a file protector driver module.

4. The method of claim 1 , wherein the one or more control points are further associated with events comprising at least one of: create a file, clean up a file, close a file, duplicate a handle, rename a file, delete a file, and create a thread.

5. The method of claim 1 , further comprising:

responsive to receiving the indication that the execution of the first process is malicious, performing a remedial action comprising restoration of a file modified by the first process and termination of the first process.

6. A system for detecting a malicious application, comprising:

a memory device; and

a processor coupled to the memory device and configured to:

detect a first process has been launched on a computing device;

monitor at least one thread associated with the first process using one or more control points of the first process;

receive from the first process an execution stack associated with the one or more control points of the first process; and

responsive to detecting activity on the one or more control points of the first process, wherein the one or more control points are associated with a system call to create a remote thread that runs in a virtual address space of a second process, which is a shared-service process configured to import third-party processes to be embedded in the shared-service process as separate threads, generate an indication that the execution of the first process is malicious by applying a machine learning classifier to the received execution stack associated with the one or more control points of the first process.

7. The system of claim 6 , wherein the monitoring the at least one thread associated with the first process is performed using call stack trace monitoring.

8. The system of claim 6 , wherein the detecting the first process has launched and the monitoring the at least one thread associated with the first process is performed by a file protector driver module.

9. The system of claim 6 , wherein the one or more control points are further associated with events comprising at least one of: create a file, clean up a file, close a file, duplicate a handle, rename a file, delete a file, and create a thread.

10. The system of claim 6 , further comprising:

responsive to receiving the indication that the execution of the first process is malicious, performing a remedial action comprising restoration of a file modified by the first process and termination of the first process.

11. A non-transitory computer readable medium comprising computer executable instructions for detecting a malicious application, including instructions for:

detecting a first process has been launched on a computing device;

monitoring at least one thread associated with the first process using one or more control points of the first process;

receiving from the first process an execution stack associated with the one or more control points of the first process; and

responsive to detecting activity on the one or more control points of the first process, wherein the one or more control points are associated with a system call to create a remote thread that runs in a virtual address space of a second process, which is a shared-service process configured to import third-party processes to be embedded in the shared-service process as separate threads, generating an indication that the execution of the first process is malicious by applying a machine learning classifier to the received execution stack associated with the one or more control points of the first process.

12. The computer readable medium of claim 11 , wherein the monitoring the at least one thread associated with the first process is performed using trace monitoring.

13. The computer readable medium of claim 11 , wherein the detecting the first process has launched and the monitoring the at least one thread associated with the first process is performed by a file protector driver module.

14. The computer readable medium of claim 11 , wherein the one or more control points are further associated with events comprising at least one of: create a file, clean up a file, close a file, duplicate a handle, rename a file, delete a file, and create a thread.

15. The computer readable medium of claim 11 , further comprising:

responsive to receiving the indication that the execution of the first process is malicious, performing a remedial action comprising restoration of a file modified by the first process and termination of the first process.

Assignments (3)
REAFFIRMATION AGREEMENT Recorded Aug 28, 2022
From: ACRONIS AG; ACRONIS INTERNATIONAL GMBH; ACRONIS SCS, INC.; ACRONIS, INC.; GROUPLOGIC, INC.; NSCALED INC.; ACRONIS MANAGEMENT LLC; 5NINE SOFTWARE, INC.; ACRONIS GERMANY GMBH; ACRONIS NETHERLANDS B.V.; ACRONIS BULGARIA EOOD; DEVICELOCK, INC.; DEVLOCKCORP LTD; ACRONIS INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 061330/0818 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2022
From: STROGOV, VLADIMIR; BELOUSSOV, SERGUEI; DOD, ALEXEY; CHERNYAKOVSKY, VALERY; STUPAK, ANATOLY; ULASEN, SERGEY; GREBENNIKOV, NIKOLAY; LEVCHENKO, VYACHESLAV; PROTASOV, STANISLAV
To: ACRONIS INTERNATIONAL GMBH
Reel/Frame 060466/0360 →
SECURITY INTEREST Recorded Dec 19, 2019
From: ACRONIS INTERNATIONAL GMBH
To: MIDCAP FINANCIAL TRUST
Reel/Frame 051418/0119 →
Cited By (6)
US 12,287,866 US 12,386,951 US 12,462,020 US 12,464,020 US 12,530,449 US 12,645,787