IP Library Granted Patent US 11,106,800
Granted Patent B1
US 11,106,800 · App. 16/698,925 · Granted Aug 31, 2021

Detecting kernel exploits

Inventor: Peter Laurence Markowsky (Brooklyn, NY)
Assignee: Capsule8, Inc.
G06F21/577G06F11/0793G06F11/3093G06F11/327G06F11/3636G06F21/552G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,106,800
App. No.
16/698,925
Granted
Aug 31, 2021
Kind
B1
Abstract

A kernel is monitored for occurrence of a set of Kprobes. A determination is made that a Strategy that makes use of at least one Kprobe included in the set of Kprobes has been matched. A remedial action is taken in response to the determination. Examples of such remedial actions include generating an alert and terminating a network connection.

Claims (38)

1. A system, comprising:

a processor configured to:

monitor for an activation of a set of one or more previously attached Kprobes;

determine that a security violation corresponding to a strategy pattern match has occurred, wherein the strategy pattern comprises a set of one or more behaviors including the activation of at least one Kprobe included in the set of Kprobes, wherein the at least one activated Kprobe is indicative of a security feature having been disabled; and

take a remedial action in response to the determination that the security violation has occurred; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the processor is further configured to set a debugging tracepoint.

3. The system of claim 1 , wherein the remedial action includes generating an alert.

4. The system of claim 1 , wherein the remedial action includes terminating a network connection.

5. The system of claim 1 , wherein the strategy pattern is associated with setting a CR4 control register.

6. The system of claim 1 , wherein the strategy pattern is associated with disabling Supervisor Mode Execution Prevention (SMEP).

7. The system of claim 1 , wherein the strategy pattern is associated with disabling Supervisor Mode Access Prevention (SMAP).

8. The system of claim 1 , wherein the strategy pattern is associated with a function being called with a return address in userland.

9. The system of claim 1 , wherein the strategy pattern is associated with credential preparation.

10. The system of claim 1 , wherein the strategy pattern is associated with disabling a security module.

11. The system of claim 10 , wherein the processor is further configured to scan kernel memory to determine whether the security module has been disabled.

12. The system of claim 1 , wherein a filter for a magic cookie value is applied as a function argument to determine whether a security mechanism has been disabled.

13. The system of claim 1 , wherein at least one Kprobe included in the set of Kprobes is periodically triggered by a Sensor.

14. A method, comprising:

monitoring for an activation of a set of one or more previously attached Kprobes;

determining that a security violation corresponding to a strategy pattern match has occurred, wherein the strategy pattern comprises a set of one or more behaviors including the activation of at least one Kprobe included in the set of Kprobes, wherein the at least one activated Kprobe is indicative of a security feature having been disabled; and

taking a remedial action in response to the determination that the security violation has occurred.

15. The method of claim 14 , further comprising setting a debugging tracepoint.

16. The method of claim 14 , wherein the remedial action includes generating an alert.

17. The method of claim 14 , wherein the remedial action includes terminating a network connection.

18. The method of claim 14 , wherein the strategy pattern is associated with setting a CR 4 control register.

19. The method of claim 14 , wherein the strategy pattern is associated with disabling Supervisor Mode Execution Prevention (SMEP).

20. The method of claim 14 , wherein the strategy pattern is associated with disabling Supervisor Mode Access Prevention (SMAP).

21. The method of claim 14 , wherein the strategy pattern is associated with a function being called with a return address in userland.

22. The method of claim 14 , wherein the strategy pattern is associated with credential preparation.

23. The method of claim 14 , wherein the strategy pattern is associated with disabling a security module.

24. The method of claim 23 , further comprising scanning kernel memory to determine whether the security module has been disabled.

25. The method of claim 14 , wherein a filter for a magic cookie value is applied as a function argument to determine whether a security mechanism has been disabled.

26. The method of claim 14 , wherein at least one Kprobe included in the set of Kprobes is periodically triggered by a Sensor.

27. A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

monitoring for an activation of a set of one or more previously attached Kprobes;

determining that a security violation corresponding to a strategy pattern match has occurred, wherein the strategy pattern comprises a set of one or more behaviors including the activation of at least one Kprobe included in the set of Kprobes, wherein the at least one activated Kprobe is indicative of a security feature having been disabled; and

taking a remedial action in response to the determination that the security violation has occurred.

Assignments (4)
MERGER Recorded Nov 19, 2025
From: CAPSULE8, LLC
To: SOPHOS INC.
Reel/Frame 072966/0801 →
CHANGE OF NAME Recorded Nov 19, 2025
From: CAPSULE8, INC.
To: CAPSULE8, LLC
Reel/Frame 073333/0484 →
SECURITY INTEREST Recorded Oct 29, 2021
From: CAPSULE8, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057966/0648 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2020
From: MARKOWSKY, PETER LAURENCE
To: CAPSULE8, INC.
Reel/Frame 053091/0682 →
Continuity (2)
Provisional Application 62773892 · Nov 30, 2018
Provisional Application 62825737 · Mar 28, 2019
Cited By (1)
US 12,696,088