IP Library Granted Patent US 12,189,780
Granted Patent B1
US 12,189,780 · App. 17/348,680 · Granted Jan 7, 2025

Detecting kernel exploits

Inventor: Peter Laurence Markowsky (New York, NY)
Assignee: Capsule8, Inc.
G06F21/577G06F11/0793G06F11/3093G06F11/327G06F11/3636G06F21/552G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,189,780
App. No.
17/348,680
Filed
Jun 15, 2021
Granted
Jan 7, 2025
Kind
B1
Art Unit
2433
USPC
726/22
Abstract

Monitoring is performed for the activation of a set of one or more previously attached Kprobes. A determination is made that a strategy pattern match has occurred. The strategy pattern comprises a set of one or more behaviors including the activation of the at least one Kprobe included in the set of Kprobes. A remedial action is taken in response to the determination. Examples of such remedial actions include generating an alert and terminating a network connection.

Claims (31)

1. A system, comprising:

a memory storing instructions; and

a processor configured by the instructions stored in the memory to:

monitor a kernel of a computing node for the activation of a set of one or more previously attached Kprobes;

determine that a strategy pattern match has occurred by detecting, with an activation of at least one of the previously attached Kprobes, a modification to a bit in a control register of the computing node that disables execution prevention or access prevention in a memory of the kernel of the computing node; and

take a remedial action in response to the determination that the strategy pattern has been matched.

2. The system of claim 1 wherein the processor is further configured to set a debugging tracepoint.

3. The system of claim 1 wherein the remedial action includes generating an alert.

4. The system of claim 1 wherein the remedial action includes terminating a network connection.

5. The system of claim 1 wherein the strategy pattern is associated with setting a CR4 control register.

6. The system of claim 1 wherein the strategy pattern is associated with a function being called with a return address in userland.

7. The system of claim 1 wherein the strategy pattern is associated with credential preparation.

8. The system of claim 1 wherein the processor is further configured to scan kernel memory to determine whether a security mechanism has been disabled.

9. The system of claim 1 wherein a filter for a magic cookie value is applied as a function argument to determine whether a security mechanism has been disabled.

10. The system of claim 1 wherein at least one Kprobe included in the set of Kprobes is periodically triggered by a Sensor.

11. A method, comprising:

monitoring a kernel of a computing node for the activation of a set of one or more previously attached Kprobes;

determining that a strategy pattern match has occurred by detecting, with an activation of at least one of the previously attached Kprobes, a modification to a bit in a control register of the computing node that disables execution prevention or access prevention in a memory of the kernel of the computing node; and

taking a remedial action in response to the determination that the strategy pattern has been matched.

12. A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

monitoring a kernel of a computing node for the activation of a set of one or more previously attached Kprobes;

determining that a strategy pattern match has occurred by detecting, with an activation of at least one of the previously attached Kprobes, a modification to a bit in a control register of the computing node that disables execution prevention or access prevention in a memory of the kernel of the computing node; and

taking a remedial action in response to the determination that the strategy pattern has been matched.

13. The method of claim 11 further including setting a debugging tracepoint.

14. The method of claim 11 wherein the remedial action includes generating an alert.

15. The method of claim 11 wherein the remedial action includes terminating a network connection.

16. The method of claim 11 wherein the strategy pattern is associated with setting a CR4 control register.

17. The method of claim 11 wherein the strategy pattern is associated with a function being called with a return address in userland.

18. The method of claim 11 wherein the strategy pattern is associated with credential preparation.

19. The method of claim 11 further including scanning kernel memory to determine whether a security mechanism has been disabled.

20. The method of claim 11 further including applying a filter for a magic cookie value as a function argument to determine whether a security mechanism has been disabled.

Assignments (4)
MERGER Recorded Nov 19, 2025
From: CAPSULE8, LLC
To: SOPHOS INC.
Reel/Frame 072966/0801 →
CHANGE OF NAME Recorded Nov 19, 2025
From: CAPSULE8, INC.
To: CAPSULE8, LLC
Reel/Frame 073333/0484 →
SECURITY INTEREST Recorded Oct 29, 2021
From: CAPSULE8, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057966/0648 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2021
From: MARKOWSKY, PETER LAURENCE
To: CAPSULE8, INC.
Reel/Frame 057326/0237 →
Continuity (3)
Continuation 16698925 · Nov 27, 2019
Provisional Application 62825737 · Mar 28, 2019
Provisional Application 62773892 · Nov 30, 2018
References Cited (84)
US 4931931A · Syre et al. · 1990 [cited by applicant]
US 5991856A · Spilo · 1999 [cited by applicant]
US 8181244B2 · Boney · 2012 [cited by applicant]
US 8201243B2 · Boney · 2012 [cited by applicant]
US 8418250B2 · Morris et al. · 2013 [cited by applicant]
US 8719932B2 · Boney · 2014 [cited by applicant]
US 8726389B2 · Morris et al. · 2014 [cited by applicant]
US 8763123B2 · Morris et al. · 2014 [cited by applicant]
US 8856505B2 · Schneider · 2014 [cited by applicant]
US 9413721B2 · Morris et al. · 2016 [cited by applicant]
US 9578045B2 · Jaroch et al. · 2017 [cited by applicant]
US 9659182B1 · Roundy · 2017 [cited by applicant]
US 10033759B1 · Kabra · 2018 [cited by applicant]
US 10169571B1 · Attfield et al. · 2019 [cited by applicant]
US 10257224B2 · Jaroch et al. · 2019 [cited by applicant]
US 10284591B2 · Giuliani et al. · 2019 [cited by applicant]
US 10430591B1 · Pratt · 2019 [cited by examiner]
US 10467407B2 · Frank · 2019 [cited by applicant]
US 10599844B2 · Schmidtler et al. · 2020 [cited by applicant]
US 10685115B1 · Lieberman et al. · 2020 [cited by applicant]
US 11409869B2 · Schmidtler et al. · 2022 [cited by applicant]
US 20030023956A1 · Dulberg · 2003 [cited by applicant]
US 20030149895A1 · Choo et al. · 2003 [cited by applicant]
US 20040025015A1 · Satterlee et al. · 2004 [cited by applicant]
US 20040162061A1 · Abrol · 2004 [cited by applicant]
US 20040168173A1 · Cohen et al. · 2004 [cited by applicant]
US 20050076237A1 · Cohen · 2005 [cited by applicant]
US 20050132232A1 · Sima · 2005 [cited by applicant]
US 20050278706A1 · Garza · 2005 [cited by applicant]
US 20060230207A1 · Finkler · 2006 [cited by applicant]
US 20070055711A1 · Polyakov · 2007 [cited by examiner]
US 20070078915A1 · Gassoway · 2007 [cited by examiner]
US 20070204257A1 · Kinno · 2007 [cited by applicant]
US 20080034430A1 · Burtscher · 2008 [cited by applicant]
US 20090116651A1 · Liang · 2009 [cited by applicant]
US 20090216869A1 · Kennedy · 2009 [cited by applicant]
US 20090271863A1 · Govindavajhala et al. · 2009 [cited by applicant]
US 20100031360A1 · Seshadri · 2010 [cited by applicant]
US 20110219449A1 · St Neitzel · 2011 [cited by applicant]
US 20120204193A1 · Nethercutt · 2012 [cited by applicant]
US 20120254993A1 · Sallam · 2012 [cited by applicant]
US 20120324575A1 · Choi · 2012 [cited by applicant]
US 20150128250A1 · Lee · 2015 [cited by applicant]
US 20160042179A1 · Weingarten · 2016 [cited by applicant]
US 20160378587A1 · Zhang · 2016 [cited by applicant]
US 20160381032A1 · Hashmi · 2016 [cited by applicant]
US 20170220795A1 · Suginaka · 2017 [cited by examiner]
US 20180060569A1 · Kim · 2018 [cited by applicant]
US 20180285561A1 · Frank · 2018 [cited by applicant]
US 20190138715A1 · Shukla · 2019 [cited by applicant]
US 20190180036A1 · Shukla · 2019 [cited by applicant]
US 20190243964A1 · Shukla · 2019 [cited by applicant]
US 20190311115A1 · Lavi · 2019 [cited by applicant]
CN 106713277 · 2017 [cited by applicant]
Reves (Reeves, et al., Lightweight Intrusion Detection for Resource-Constrained Embedded Control Systems. 5th International Conference Critical Infrastructure Protection (ICCIP), Mar. 2011, pp. 31-46, 10.1007/978-3-642-… [cited by examiner]
Erlang.org (“11 Distributed Erlang”, author unknown, found at http://erlang.org/documentation/doc-5.5.1/doc/reference_manual/distributed.html, Aug. 2016) (Year: 2016). [cited by examiner]
Kurmus et al., “Quantifiable Run-time Kernel Attack Surface Reduction”, Detection of Intrusions and Malware, and Vulnerability Assessment, 2014, vol. 8550, ISBN : 978-3-319-08508-1 (Year: 2014). [cited by examiner]
Alexander M. Hoole, Security Vulnerability Verification through Contract-Based Assertion Monitoring at Runtime, 2016. [cited by applicant]
Andrey Konovalov, News and Updates from the Project Zero Team at Google, 2015. [cited by applicant]
Ashwin Ramaswamy, Detecting Kernel Rootkits, Masters Thesis Proposal Dartmouth Computer Science Technical Report TR2008-627, Sep. 2, 2008. [cited by applicant]
Bala et al., Session Hijacking Prevention Using Magic Cookie with MAC, Asian Journal of Electrical Science, Aug. 2015. [cited by applicant]
Bjorn Dobel, Request Tracking in DROPS, Technische Universitat Dresden Fakultat Informatik, May 30, 2006. [cited by applicant]
David Long, Kprobes Event Tracing on Armv8, Linaro, Dec. 16, 2016. [cited by applicant]
Hossain et al., Sleuth: Real-time Attack Scenario Reconstruction from COTS Audit Data, Proceedings of the 26th USENIX Security Symposium, Aug. 2017. [cited by applicant]
Lu et al., Unleashing Use-Before-Initialization Vulnerabilities in the Linux Kernel Using Targeted Stack Spraying, Internet Society, 2017. [cited by applicant]
Luhtala et al., Instrumentation of a Linux-Based Mobile Device, 2015. [cited by applicant]
Pohlack et al., Towards Runtime Monitoring in Real-Time Systems, Proceedings of the Eighth Real-Time Linux Workshop, 2006. [cited by applicant]
Sudhanshu Goswami, An Introduction to KProbes, Apr. 18, 2005. [cited by applicant]
Sun et al., The Study of Data Collecting Based on Kprobe, 2011 Fourth International Symposium on Computational Intelligence and Design, 2011. [cited by applicant]
Tian et al., An Online Approach to Defeating Return-Oriented-Programming Attacks, Cyberspace Safety and Security: 9th International Symposium, Oct. 2017. [cited by applicant]
Author Unknown, “Checking the Current TTY”, tldp.org, https://web.archive.org/web/20180103035946/https:/tldp.org/HOWTO/Bash-Prompt-HOWTO/x721.html Jan. 3, 2018 , 1 page. [cited by applicant]
“U.S. Appl. No. 16/698,918 Notice of Allowance mailed Mar. 1, 2021”, 11 pages. [cited by applicant]
“U.S. Appl. No. 16/698,920 Final Office Action mailed Sep. 2, 2020”, 16 Pages. [cited by applicant]
“U.S. Appl. No. 16/698,920 Non-Final Office Action mailed Nov. 18, 2020”, 17 pages. [cited by applicant]
“U.S. Appl. No. 16/698,920 Non-Final Office Action mailed Apr. 1, 2020”, 16 Pages. [cited by applicant]
“U.S. Appl. No. 16/698,920 Notice of Allowance mailed Apr. 21, 2021”, 13 pages. [cited by applicant]
“U.S. Appl. No. 16/698,925 Final Office Action mailed Sep. 24, 2020”, 14 pages. [cited by applicant]
“U.S. Appl. No. 16/698,925 Non-Final Office Action mailed Jun. 5, 2020”, 15 pages. [cited by applicant]
“U.S. Appl. No. 16/698,925 Notice of Allowance mailed May 5, 2021”, 8 pages. [cited by applicant]
“U.S. Appl. No. 17/348,671 Non-Final Office Action mailed Sep. 15, 2022”, 15 pages. [cited by applicant]
“U.S. Appl. No. 17/336,128 Non-Final Office Action mailed Mar. 31, 2023”, 18 pages. [cited by applicant]
“U.S. Appl. No. 17/348,671 Notice of Allowance mailed Mar. 16, 2023”, 10 pages. [cited by applicant]
“U.S. Appl. No. 17/336,128 Notice of Allowance mailed Nov. 21, 2023”, 10 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 18/366,195 Non-Final Office Action mailed Sep. 5, 2024”, 17 pages. [cited by applicant]
Cited By (1)
US 12,696,088