IP Library › Granted Patent US 11,397,811
Granted Patent B2
US 11,397,811 · App. 16/833,766 · Granted Jul 26, 2022

System and method for application tamper discovery

Inventors: Jon Whitmore (Washington, DC); Kevin Nieman (Vienna, VA)
Assignee: Capital One Services, LLC
G06F21/566G06F21/52G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,397,811
App. No.
16/833,766
Granted
Jul 26, 2022
Kind
B2
Abstract

A system and method for early detection of a compromised client device includes a tamper detection service configured to monitor modifications to resource access privileges over time to identify unusual variations in jailbreak status that indicate compromise of the client device. For example, the tamper detection service may monitor the jailbreak status of system files over time to expose attempts to hide the jailbreak status of a protected resource. To validate that malware is attempting to hide the jailbreak status of a protected resources, the tamper detection process may launch multiple different resource accesses, targeting the protected resource, to determine whether different accessibility results are returned, indicating a compromised device.

Claims (33)

1. A computer-implemented method, comprising:

executing, by a processor of a mobile device, a first function on a set of protected resources, the first function comprising attempting to access each protected resource of the set of protected resource and generating first function access results;

executing, by the processor of the mobile device, a second function on the set of protected resources, the second function comprising attempting to access each protected resource of the set of protected resource and generating second function access results, wherein the first function and the second function are implemented in different levels of programming language code, the second function is implemented in a lower level of programming language code, and the first function is implemented in a higher level of programming language code;

determining, by the processor of the mobile device, a difference between the first function access results and the second function access results; and

selectively disabling an application in response to determining the difference between the first function access results and the second function access results.

2. The computer-implemented method of claim 1 , wherein selectively disabling access comprises disabling access by the application on the mobile device, to a server or to both.

3. The computer-implemented method of claim 1 , wherein the higher level of programming language code comprises Java, FORTRAN, Objective-C, or Swift.

4. The computer-implemented method of claim 1 , wherein the lower level of programming language code comprises machine code, assembly code, or operating system code.

5. The computer-implemented method of claim 1 , wherein the set of protected resources comprises at least one of a system file, a directory, a library, a variable, a database, a function, an application, a service, other restricted resource, or a combination thereof.

6. The computer-implemented method of claim 1 , wherein executing the first function comprises issuing a series of access requests to the set of protected resources, the series of access requests including an access request for each protected resource of the set of protected resources.

7. The computer-implemented method of claim 1 , wherein executing the second function comprises issuing a series of lower-level access requests to the set of protected resources, the series of lower-level access requests including a lower-level access request for each protected resource of the set of protected resources.

8. A computing device, comprising:

memory to store instructions;

processing circuitry coupled with the memory, the processing circuitry configured to execute the instructions to:

execute a first function on a set of protected resources, the first function to attempt to access each protected resource of the set of protected resource and generate first results;

execute a second function on the set of protected resources, the second function to attempt to access each protected resource of the set of protected resource and generate second results, wherein the second function is implemented in a lower level of programming language code, and the first function is implemented in a higher level of programming language code;

detect a difference between the first results and the second results; and

perform an operation on an application in response to determining the difference.

9. The computing device of claim 8 , wherein the operation comprises the processing circuitry to selectively disable access to the application on the mobile device, to a server or to both.

10. The computing device of claim 8 , wherein the higher level of programming language code comprises Java, FORTRAN, Objective-C, or Swift.

11. The computing device of claim 8 , wherein the lower level of programming language code comprises machine code, assembly code, or operating system code.

12. The computing device of claim 8 , wherein the set of protected resources comprises at least one of a system file, a directory, a library, a variable, a database, a function, an application, a service, other restricted resource, or a combination thereof.

13. The computing device of claim 8 , wherein the processing circuitry to execute the first function to issue a series of access requests to the set of protected resources, the series of access requests including an access request for each protected resource of the set of protected resources.

14. The computing device of claim 8 , wherein the processing circuitry to execute the second function to issue a series of lower-level access requests to the set of protected resources, the series of lower-level access requests including a lower-level access request for each protected resource of the set of protected resources.

15. At least one non-transitory computer-readable medium comprising a set of instructions that, in response to being executed on a computing system, cause the computing system to:

execute a first function and a second function on a set of protected resources, the first function to generate first results based on attempting to access each protected resource of the set of protected resource, and the second function to generate second results based on the second function attempting to access each protected resource of the set of protected resource, wherein the second function is implemented in a lower level of programming language code, and the first function is implemented in a higher level of programming language code;

compare the first results and the second results;

perform an operation on an application in response to detecting difference between the first results and the second results.

16. The at least one non-transitory computer-readable medium of claim 15 , wherein the operation comprises the computing system to selectively disable access to the application on the mobile device, to a server or to both.

17. The at least one non-transitory computer-readable medium of claim 15 , wherein the higher level of programming language code comprises Java, FORTRAN, Objective-C, or Swift and the lower level of programming language code comprises machine code, assembly code, or operating system code.

18. The at least one non-transitory computer-readable medium of claim 15 , wherein the computing system to:

execute the first function to issue a series of access requests to the set of protected resources, the series of access requests including an access request for each protected resource of the set of protected resources; and

execute the second function to issue a series of lower-level access requests to the set of protected resources, the series of lower-level access requests including a lower-level access request for each protected resource of the set of protected resources.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 30, 2020
From: WHITMORE, JON; NIEMAN, KEVIN
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 052259/0166 →
Continuity (2)
Continuation 16576303 · Sep 19, 2019
Related Publication 20210089655A1 · Mar 25, 2021