IP Library Granted Patent US 11,436,319
Granted Patent B2
US 11,436,319 · App. 16/752,825 · Granted Sep 6, 2022

Automated detection of user device security risks related to process threads and corresponding activity

Inventors: Vishnu C. Pedasingu (Bangalore, IN); Phaneendra Ksl (Bangalore, IN); Gaurav Bansal (Bangalore, IN)
Assignee: RSA Security LLC
G06F21/54G06F21/552G06F21/566
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,436,319
App. No.
16/752,825
Granted
Sep 6, 2022
Kind
B2
Abstract

Methods, apparatus, and processor-readable storage media for automated detection of user device security risks related to process threads and corresponding activity are provided herein. An example computer-implemented method includes obtaining information pertaining to processes running on a user device; obtaining information pertaining to images loaded into at least one memory associated with at least one of the processes running on the user device; obtaining information pertaining to threads created in connection with at least one of the processes running on the user device; automatically identifying at least one of the threads as a security risk by processing the information pertaining to the images and the information pertaining to the threads; and performing at least one automated action based on the identification of at least one of the one or more threads as a security risk.

Claims (36)

1. A computer-implemented method comprising:

obtaining information pertaining to one or more processes running on a user device;

obtaining information pertaining to one or more images loaded into at least one memory associated with at least one of the one or more processes running on the user device;

obtaining information pertaining to one or more threads created in connection with at least one of the one or more processes running on the user device;

automatically identifying at least one of the one or more threads as a security risk by analyzing a memory start address attributed to a thread and determining the memory start address attributed to the thread is not within a memory address range of at least one of the one or more images loaded into the at least one memory; and

performing at least one automated action based at least in part on the identification of at least one of the one or more threads as a security risk;

wherein the method is performed by at least one processing device comprising a processor coupled to a memory.

2. The computer-implemented method of claim 1 , wherein performing at least one automated action includes providing contextual data about an action that occurred on the user device to a server, wherein the contextual data includes file-related information, process-related information, or registry-related information.

3. The computer-implemented method of claim 1 , wherein automatically identifying the at least one thread as a security risk comprises automatically identifying one or more activities carried out by the at least one thread identified as a security risk.

4. The computer-implemented method of claim 1 , wherein performing the at least one automated action comprises automatically outputting the identification of at least one of the one or more threads as a security risk to a network security server.

5. The computer-implemented method of claim 4 , further comprising:

automatically performing one or more remedial actions with respect to the user device in response to input from the network security server.

6. The computer-implemented method of claim 1 , wherein obtaining information pertaining to the one or more images comprises registering to a kernel callback using at least one application programming interface.

7. The computer-implemented method of claim 1 , wherein the information pertaining to the one or more images comprises at least one of: process association information, image path information, and image size information.

8. The computer-implemented method of claim 1 , wherein obtaining information pertaining to the one or more threads comprises registering to a kernel callback using at least one application programming interface.

9. The computer-implemented method of claim 1 , wherein the information pertaining to the one or more threads comprises at least one of: identification of the process creating a given one of the one or more threads, identification of the process in which a given one of the one or more threads is created, a memory start address, a memory end address, and thread identifier information.

10. The computer-implemented method of claim 1 , wherein the information pertaining to the one or more processes running on the user device comprises at least one of: path-related information, filename information, and user information.

11. The computer-implemented method of claim 1 , wherein the at least one processing device comprises the user device.

12. A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device:

to obtain information pertaining to one or more processes running on a user device;

to obtain information pertaining to one or more images loaded into at least one memory associated with at least one of the one or more processes running on the user device;

to obtain information pertaining to one or more threads created in connection with at least one of the one or more processes running on the user device;

to automatically identify at least one of the one or more threads as a security risk by analyzing a memory start address attributed to a thread and determining the memory start address attributed to the thread is not within a memory address range of at least one of the one or more images loaded into the at least one memory; and

to perform at least one automated action based at least in part on the identification of at least one of the one or more threads as a security risk.

13. The non-transitory processor-readable storage medium of claim 12 , wherein the program code causes the at least one processing device to perform the at least one automated action by providing contextual data about an action that occurred on the user device to a server, wherein the contextual data includes file-related information, process-related information, or registry-related information.

14. The non-transitory processor-readable storage medium of claim 12 , wherein automatically identifying the at least one thread as a security risk comprises automatically identifying one or more activities carried out by the at least one thread identified as a security risk.

15. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the at least one processing device being configured:

to obtain information pertaining to one or more processes running on a user device;

to obtain information pertaining to one or more images loaded into at least one memory associated with at least one of the one or more processes running on the user device;

to obtain information pertaining to one or more threads created in connection with at least one of the one or more processes running on the user device;

to automatically identify at least one of the one or more threads as a security risk by analyzing a memory start address attributed to a thread and determining the memory start address attributed to the thread is not within a memory address range of at least one of the one or more images loaded into the at least one memory; and

to perform at least one automated action based at least in part on the identification of at least one of the one or more threads as a security risk.

16. The apparatus of claim 15 , wherein the at least one processing device is configured to perform the at least one automated action by providing contextual data about an action that occurred on the user device to a server, wherein the contextual data includes file-related information, process-related information, or registry-related information.

17. The apparatus of claim 15 , wherein automatically identifying the at least one thread as a security risk comprises automatically identifying one or more activities carried out by the at least one thread identified as a security risk.

Assignments (21)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 70587/0885 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075031/0394 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
NOTICE OF PARTIAL TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN TRADEMARK RIGHTS AND PATENT RIGHTS RECORDED AT REEL/FRAME: 056098/0534 Recorded Jun 3, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 071484/0819 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2025
From: RSA SECURITY LLC
To: NETWITNESS SECURITY LLC
Reel/Frame 071495/0168 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Mar 21, 2025
From: RSA SECURITY LLC; RSA SECURITY USA LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 070587/0885 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052216/0758) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0680 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST AF REEL 052243 FRAME 0773 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0152 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 053702/0124 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 26, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 052243/0773 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 24, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052216/0758 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2020
From: PEDASINGU, VISHNU C.; KSL, PHANEENDRA; BANSAL, GAURAV
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 051626/0312 →