IP Library › Granted Patent US 11,403,427
Granted Patent B2
US 11,403,427 · App. 17/028,949 · Granted Aug 2, 2022

Methods and systems for reinforcement learning of post-attack security hardening passes

Inventors: Timothy Potteiger (Baltimore, MD); Bradley Potteiger (Baltimore, MD); Michael Bryant (Brentwood, TN)
Assignee: Arms Cyber Defense, Inc.
G06F21/629G06F11/3428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,403,427
App. No.
17/028,949
Granted
Aug 2, 2022
Kind
B2
Abstract

Various embodiments of methods, systems and computer program products described herein are directed to a Security Engine. The Security Engine provides for post-attack security upgrades of an application by selecting specific security hardening passes to be applied to a pre-attack state of the application. According to various embodiments, the Security Engine receives a pre-attack state of a first instance of an application in response to an action by an attack source. The Security Engine selects one or more security hardening passes to be applied to the pre-attack state. The Security Engine sends an identification of the selected security hardening passes to be applied to a second instance of the application running at the pre-attack state.

Claims (62)

1. A computer-implemented method, comprising:

receiving a pre-attack state of a first instance of an application in response to an action by an attack source;

selecting one or more security hardening passes to be applied to the pre-attack state; and

sending an identification of the selected security hardening passes to be applied to a second instance of the application running at the pre-attack state,

wherein selecting one or more security hardening passes to be applied to the pre-attack state comprises:

selecting a first security hardening pass associated with a first type of program efficiency benchmark;

applying the first security hardening pass to the pre-attack state; and

validating the pre-attack state with the first security hardening pass satisfies a first application performance threshold that corresponds with the first type of program efficiency benchmark.

2. The computer-implemented method of claim 1 , further comprising:

based on satisfying the first application performance threshold:

selecting a second security hardening passes associated with a second type of program efficiency benchmark, the second type of program efficiency benchmark being different than the first type of program efficiency benchmark;

applying the second security hardening pass to the pre-attack state with the first security hardening pass; and

validating the pre-attack state with the first and second security hardening passes satisfies a second application performance threshold that corresponds with the first and the second types of program efficiency benchmarks.

3. The computer-implemented method of claim 1 , wherein receiving a pre-attack state of a first instance of an application in response to an action by an attack source comprises:

receiving an indication of a detected memory access violation of memory used by a first process for the first instance of the application.

4. The computer-implemented method of claim 3 , wherein receiving an indication of a detected memory access violation of memory used by a first process comprises:

receiving an indication of a detected memory access violation of diversified memory used by the first process, the memory access violation detected by a parent process of the first process.

5. The computer-implemented method of claim 4 , wherein a second process for the second instance of the application running at the pre-attack state comprises a child process of the parent process; and

wherein sending an identification of the selected security hardening passes to be applied to a second instance of the application running at the pre-attack state comprises:

sending the identification of the selected security hardening passes to be applied to the second process by the parent process, the second process running idle at the pre-attack state while the first process fails due to the attack source.

6. The computer-implemented method of claim 4 , wherein the parent process diversified the memory used by the first process prior to the memory access violation.

7. A system comprising one or more processors, and a non-transitory computer-readable medium including one or more sequences of instructions that, when executed by the one or more processors, cause the system to perform operations comprising:

receiving a pre-attack state of a first instance of an application in response to an action by an attack source;

selecting one or more security hardening passes to be applied to the pre-attack state; and

sending an identification of the selected security hardening passes to be applied to a second instance of the application running at the pre-attack state,

wherein selecting one or more security hardening passes to be applied to the pre-attack state comprises:

selecting a first security hardening pass associated with a first type of program efficiency benchmark;

applying the first security hardening pass to the pre-attack state; and

validating the pre-attack state with the first security hardening pass satisfies a first application performance threshold that corresponds with the first type of program efficiency benchmark.

8. The system of claim 7 , further comprising:

based on satisfying the first application performance threshold:

selecting a second security hardening passes associated with a second type of program efficiency benchmark, the second type of program efficiency benchmark being different than the first type of program efficiency benchmark;

applying the second security hardening pass to the pre-attack state with the first security hardening pass; and

validating the pre-attack state with the first and second security hardening passes satisfies a second application performance threshold that corresponds with the first and the second types of program efficiency benchmarks.

9. The system of claim 7 , wherein receiving a pre-attack state of a first instance of an application in response to an action by an attack source comprises:

receiving an indication of a detected memory access violation of memory used by a first process for the first instance of the application.

10. The system of claim 9 , wherein receiving an indication of a detected memory access violation of memory used by a first process comprises:

receiving an indication of a detected memory access violation of diversified memory used by the first process, the memory access violation detected by a parent process of the first process.

11. The system of claim 10 , wherein a second process for the second instance of the application running at the pre-attack state comprises a child process of the parent process; and

wherein sending an identification of the selected security hardening passes to be applied to a second instance of the application running at the pre-attack state comprises:

sending the identification of the selected security hardening passes to be applied to the second process by the parent process, the second process running idle at the pre-attack state while the first process fails due to the attack source.

12. The system of claim 10 , wherein the parent process diversified the memory used by the first process prior to the memory access violation.

13. A computer program product comprising a non-transitory computer-readable medium having a computer-readable program code embodied therein to be executed by one or more processors, the program code including instructions to:

receiving a pre-attack state of a first instance of an application in response to an action by an attack source;

selecting one or more security hardening passes to be applied to the pre-attack state; and

sending an identification of the selected security hardening passes to be applied to a second instance of the application running at the pre-attack state,

wherein selecting one or more security hardening passes to be applied to the pre-attack state comprises:

selecting a first security hardening pass associated with a first type of program efficiency benchmark;

applying the first security hardening pass to the pre-attack state; and

validating the pre-attack state with the first security hardening pass satisfies a first application performance threshold that corresponds with the first type of program efficiency benchmark.

14. The computer program product of claim 13 , further comprising:

based on satisfying the first application performance threshold:

selecting a second security hardening passes associated with a second type of program efficiency benchmark, the second type of program efficiency benchmark being different than the first type of program efficiency benchmark;

applying the second security hardening pass to the pre-attack state with the first security hardening pass; and

validating the pre-attack state with the first and second security hardening passes satisfies a second application performance threshold that corresponds with the first and the second types of program efficiency benchmarks.

15. The computer program product of claim 13 , wherein receiving a pre-attack state of a first instance of an application in response to an action by an attack source comprises:

receiving an indication of a detected memory access violation of memory used by a first process for the first instance of the application.

16. The computer program product of claim 15 , wherein receiving an indication of a detected memory access violation of memory used by a first process comprises:

receiving an indication of a detected memory access violation of diversified memory used by the first process, the memory access violation detected by a parent process of the first process.

17. The computer program product of claim 16 , wherein a second process for the second instance of the application running at the pre-attack state comprises a child process of the parent process; and

wherein sending an identification of the selected security hardening passes to be applied to a second instance of the application running at the pre-attack state comprises:

sending the identification of the selected security hardening passes to be applied to the second process by the parent process, the second process running idle at the pre-attack state while the first process fails due to the attack source, wherein the parent process diversified the memory used by the first process prior to the memory access violation.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2020
From: POTTEIGER, TIMOTHY; POTTEIGER, BRADLEY; BRYANT, MICHAEL
To: ARMS CYBER DEFENSE, INC.
Reel/Frame 053851/0421 →
Continuity (2)
Provisional Application 63077471 · Sep 11, 2020
Related Publication 20220083677A1 · Mar 17, 2022
Cited By (1)
US 12,596,812