IP Library Granted Patent US 11,943,238
Granted Patent B1
US 11,943,238 · App. 17/336,128 · Granted Mar 26, 2024

Process tree and tags

Inventor: Brandon M. Edwards (Brooklyn, NY)
Assignee: Capsule8, Inc.
H04L63/1416G06F21/554G06F21/577H04L63/1425H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,943,238
App. No.
17/336,128
Granted
Mar 26, 2024
Kind
B1
Abstract

Information associated with a process is received. At least a portion of the received information is used to modify a Process Tree. Modifying the Process Tree includes at least one of: (1) adding a Tag to the Process Tree and (2) modifying a Tag in the Process Tree. An Alert is generated based at least in part in response to determining that a Strategy has been matched.

Claims (40)

1. A system, comprising:

a memory storing instructions: and

a processor coupled to the memory and configured by the instructions to:

receive information associated with a process event including a transition;

use at least a portion of the received information to modify a Process Tree_by propagating tag information according to tag propagation logic, wherein modifying the Process Tree includes at least one of:

(1) adding a Tag to the Process Tree for a process created by the process event, and

(2) modifying an original authorized shell Tag in the Process Tree for an existing process exited by the process event;

determine that at least a portion of the Process Tree matches a malware pattern: and

generate an Alert, based at least in part in response to determining that the malware pattern has been matched.

2. The system of claim 1 , wherein the received information indicates that the process has been forked.

3. The system of claim 1 , wherein the received information indicates that the process has been initialized.

4. The system of claim 1 , wherein the received information indicates that the process has been exited.

5. The system of claim 1 , wherein, in response to receiving the information, the processor is configured to determine whether any Tags are associated with the process.

6. The system of claim 5 , wherein the processor is further configured to determine whether any Tags determined to be associated with the process expect to have a callback associated with an Event.

7. The system of claim 1 , wherein the information includes a change to at least one of a UID and a GID.

8. The system of claim 1 , wherein the Alert indicates that an insecure privilege escalation has occurred.

9. The system of claim 1 , wherein the Alert indicates an original user that is different from a user currently associated with the process.

10. The system of claim 1 , wherein the Process Tree uses a timeout-driven hash map.

11. The system of claim 1 , wherein the information is received from a sensor executing in a user space without kernel modification.

12. The system of claim 1 , wherein the information is read out of a ring buffer.

13. The system of claim 1 , wherein the processor is further configured to propagate an Alert group to children of the process.

14. The system of claim 1 , wherein the malware pattern comprises a cross-node Strategy.

15. The system of claim 1 , wherein the Alert includes a lineage associated with the process.

16. The system of claim 1 , wherein, in response to the Alert being generated, a remedial action is taken.

17. The system of claim 16 , wherein the remedial action includes contacting a user associated with the process.

18. A method, comprising:

receiving information associated with a process event including a transition;

using at least a portion of the received information to modify a Process Tree_by propagating tag information according to tag propagation logic, wherein modifying the Process Tree includes at least one of:

(1) adding a Tag to the Process Tree for a process created by the process event, and

(2) modifying an original authorized shell Tag in the Process Tree for an existing process exited by the process event;

determining that at least a portion of the Process Tree matches a malware pattern: and

generating an Alert, based at least in part in response to determining that the malware pattern has been matched.

19. A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving information associated with a process event including a transition;

using at least a portion of the received information to modify a Process Tree by propagating tag information according to tag propagation logic, wherein modifying the Process Tree includes at least one of:

(1) adding a Tag to the Process Tree for a process created by the process event, and

(2) modifying an original authorized shell Tag in the Process Tree for an existing process exited by the process event;

determining that at least a portion of the Process Tree matches a malware pattern; and

generating an Alert, based at least in part in response to determining that the malware pattern has been matched.

20. The computer program product of claim 19 , wherein, in response to receiving the information, determining whether any Tags are associated with the process.

Assignments (4)
MERGER Recorded Nov 19, 2025
From: CAPSULE8, LLC
To: SOPHOS INC.
Reel/Frame 072966/0801 →
CHANGE OF NAME Recorded Nov 19, 2025
From: CAPSULE8, INC.
To: CAPSULE8, LLC
Reel/Frame 073333/0484 →
SECURITY INTEREST Recorded Oct 29, 2021
From: CAPSULE8, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057966/0648 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2021
From: EDWARDS, BRANDON M.
To: CAPSULE8, INC.
Reel/Frame 057325/0781 →
Continuity (3)
Continuation 16698918 · Nov 27, 2019
Provisional Application 62825737 · Mar 28, 2019
Provisional Application 62773892 · Nov 30, 2018