IP Library Granted Patent US 11,171,987
Granted Patent B2
US 11,171,987 · App. 16/476,938 · Granted Nov 9, 2021

Protecting computing devices from a malicious process by exposing false information

Inventors: Mordechai Guri (Nof Ayalon, IL); Ronen Yehoshua (Matan, IL); Michael Gorelik (Brookline, MA)
Assignee: Morphisec Information Security 2014 Ltd.
H04L63/1491H04L63/145H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,171,987
App. No.
16/476,938
Granted
Nov 9, 2021
Kind
B2
Abstract

Various automated techniques are described herein for protecting computing devices from malicious code injection and execution by providing a malicious process with incorrect information regarding the type and/or version and/or other characteristics of the operating system and/or the targeted program and/or the targeted computing device. The falsified information tricks the malicious process into injecting shellcode that is incompatible with the targeted operating system, program and/or computing device. When the incompatible, injected shellcode attempts to execute, it fails as a result of the incompatibility, thereby protecting the computing device.

Claims (68)

1. A method for protecting a computing device from shellcode injection and execution, comprising:

detecting a query that requests information about at least one of an operating system or a first computing process executing on the computing device, the query being issued from a second computing process;

falsifying the information about the at least one of the operating system or the first computing process; and

providing the falsified information to the second computing process, wherein the falsified information causes execution of a shellcode to fail, the shellcode comprising code that has been injected into the first computing process and that is associated with the second computing process.

2. The method of claim 1 , wherein the information comprises at least one of:

a type of the at least one of the operating system or the first computing process;

a version of the at least one of the operating system or the first computing process; or

an identifier of the at least one of the operating system or the first computing process.

3. The method of claim 1 , wherein the second computing process comprises at least one of:

a malicious website;

a network scanner; or

a malicious macro.

4. The method of claim 1 , wherein the detecting step comprises:

hooking a procedure call issued from the second computing process that requests the information.

5. The method of claim 1 , wherein execution of the shellcode causes an exception to be thrown by the first computing device.

6. The method of claim 5 , further comprising:

determining that a malicious attack has occurred in response to detecting the exception; and

performing an action to neutralize the shellcode.

7. The method of claim 6 , wherein the performing step comprises:

terminating the shellcode;

suspending the shellcode;

activating an anti-virus program;

recording to an event log an event that indicates that the shellcode attempted execution; or

prompting a user of the computing device to specify an operation to perform.

8. A system, comprising:

one or more processors; and

a memory coupled to the one or more processors, the memory storing instructions, which, when executed by the one or more processors, cause the one or more processors to perform operations, the operations comprising:

detecting a query that requests information about at least one of an operating system or a first computing process executing on the computing device, the query being issued from a second computing process;

falsifying the information about the at least one of the operating system or the first computing process; and

providing the falsified information to the second computing process, wherein the falsified information causes execution of a shellcode to fail, the shellcode comprising code that has been injected into the first computing process and that is associated with the second computing process.

9. The system of claim 8 , wherein the information comprises at least one of:

a type of the at least one of the operating system or the first computing process;

a version of the at least one of the operating system or the first computing process; or

an identifier of the at least one of the operating system or the first computing process.

10. The system of claim 8 , wherein the second computing process comprises at least one of:

a malicious website;

a network scanner; or

a malicious macro.

11. The system of claim 8 , wherein the detecting step comprises:

hooking a procedure call issued from the second computing process that requests the information.

12. The system of claim 8 , wherein execution of the shellcode causes an exception to be thrown by the first computing device.

13. The system of claim 12 , the operations further comprising:

determining that a malicious attack has occurred in response to detecting the exception; and

performing an action to neutralize the shellcode.

14. The system of claim 13 , wherein the performing step comprises:

terminating the shellcode;

suspending the shellcode;

activating an anti-virus program;

recording to an event log an event that indicates that the shellcode attempted execution; or

prompting a user of the computing device to specify an operation to perform.

15. A computer-readable storage medium having program instructions recorded thereon that, when executed by a processing device, perform a method for protecting a computing device from shellcode injection and execution, the method comprising:

detecting a query that requests information about at least one of an operating system or a first computing process executing on the computing device, the query being issued from a second computing process;

falsifying the information about the at least one of the operating system or the first computing process; and

providing the falsified information to the second computing process, wherein the falsified information causes execution of a shellcode to fail, the shellcode comprising code that has been injected into the first computing process and that is associated with the second computing process.

16. The computer-readable storage medium of claim 15 , wherein the information comprises at least one of:

a type of the at least one of the operating system or the first computing process;

a version of the at least one of the operating system or the first computing process; or

an identifier of the at least one of the operating system or the first computing process.

17. The computer-readable storage medium of claim 15 , wherein the second computing process comprises at least one of:

a malicious website;

a network scanner; or

a malicious macro.

18. The computer-readable storage medium of claim 15 , wherein the detecting step comprises:

hooking a procedure call issued from the second computing process that requests the information.

19. The computer-readable storage medium of claim 15 , wherein execution of the shellcode causes an exception to be thrown by the first computing device.

20. The computer-readable storage medium of claim 19 , wherein the method further comprises:

determining that a malicious attack has occurred in response to detecting the exception; and

performing an action to neutralize the shellcode.

Assignments (3)
SECURITY INTEREST Recorded Oct 1, 2024
From: MORPHISEC INFORMATION SECURITY 2014 LTD
To: HERCULES CAPITAL, INC.
Reel/Frame 068758/0581 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 1ST INVENTOR'S LAST NAME PREVIOUSLY RECORDED AT REEL: 051024 FRAME: 0794. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded Jul 20, 2021
From: GORELIK, MICHAEL; GURI, MORDECHAI; YEHOSHUA, RONEN
To: MORPHISEC INFORMATION SECURITY 2014 LTD.
Reel/Frame 056926/0871 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2019
From: GORELICK, MICHAEL; GURI, MORDECHAI; YEHOSHUA, RONEN
To: MORPHISEC INFORMATION SECURITY 2014 LTD.
Reel/Frame 051024/0794 →
Continuity (2)
Provisional Application 62445020 · Jan 11, 2017
Related Publication 20190334949A1 · Oct 31, 2019
Cited By (1)
US 12,502,749