IP Library › Granted Patent US 12,406,060
Granted Patent B2
US 12,406,060 · App. 17/664,009 · Granted Sep 2, 2025

Automated interpreted application control for workloads

Inventor: Satya V. Gupta (Dublin, CA)
Assignee: Virsec Systems, Inc.
G06F21/563G06F21/562G06F21/566G06F21/577G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,406,060
App. No.
17/664,009
Granted
Sep 2, 2025
Kind
B2
Abstract

Embodiments provide functionality to protect computing workloads from script-based attacks. Upon receipt, at a workload, of a command to commence execution of code of a script, an embodiment determines whether (i) permissions of a user issuing the command comply with a permissions security standard, (ii) an identifier of an interpreter supporting the script is included in an approved interpreter list, (iii) an identifier of a selected parameter of the interpreter is included in an approved parameter list, and (iv) an identifier of the script is included in an approved list of executables. If all of the aforementioned checks pass, such an embodiment allows execution of the code of the script; otherwise, execution is denied, thereby protecting the workload in an event of a script-based attack.

Claims (70)

1. A computer-implemented method of protecting a computing workload from script-based attacks, the method comprising:

receiving, at a workload, a command to commence execution of code of a script;

determining whether:

(i) permissions of a user issuing the command comply with a permissions security standard;

(ii) an identifier of an interpreter supporting the script is included in an approved interpreter list;

(iii) an identifier of a selected parameter of the interpreter is included in an approved parameter list, wherein the selected parameter modifies operations performed by the interpreter and the identifier of the selected parameter is distinct from the identifier of the interpreter; and

(iv) an identifier of the script is included in an approved list of executables; and

allowing or denying the execution of the code of the script based on the determining, thereby protecting the workload from script-based attacks.

2. The method of claim 1 wherein at least one of the identifier of the interpreter, the identifier of the selected parameter, and the identifier of the script, includes a checksum.

3. The method of claim 1 further comprising:

receiving an identifier of an approved interpreter, or parameter thereof, from a vendor of the approved interpreter; and

adding the identifier of the approved interpreter, or parameter thereof, to the approved interpreter list, or the approved parameter list.

4. The method of claim 1 further comprising:

receiving an identifier of an approved script from a vendor of the approved script; and

adding the identifier of the approved script to the approved list of executables.

5. The method of claim 1 wherein allowing or denying the execution of the code of the script further comprises:

denying the execution of the code of the script in response to the received command not being present in a list of commands known to be used by the workload at runtime.

6. The method of claim 1 wherein allowing or denying the execution of the code of the script is further based on determining whether the user is positively authorized to execute the script based on permissions of the user and permissions of the script.

7. The method of claim 1 wherein allowing or denying the execution of the code of the script further comprises:

denying the execution of the code of the script in response to a process to be spawned by the script matching a process in a list of known malicious processes.

8. The method of claim 1 wherein allowing or denying the execution of the code of the script further comprises:

denying the execution of the code of the script in response to at least one of the script, a process to be spawned by the script and a library to be loaded during the execution of the script, including a known vulnerability.

9. The method of claim 1 further comprising, in response to allowing the execution of the code of the script:

intercepting a given process spawned during the execution of the code of the script;

tokenizing the received command;

comparing tokens of the tokenized received command with entries in an allow-list database; and

based on the comparing, maintaining the execution, or suspending the execution, of the code of the script, or indicating a result of the comparing to a user seeking to control execution of the script.

10. The method of claim 1 further comprising, in response to allowing the execution of the code of the script:

intercepting a library loaded during the execution of the script; and

in response to the library including a known vulnerability, and a disposition of the library regarding the vulnerability having not been received from a user, suspending the execution of the code of the script, or indicating the vulnerability to a user seeking to control execution of the script.

11. A system for protecting a computing workload from script-based attacks, the system comprising:

an application control policy (ACP) engine and an endpoint process monitoring client (EPMC); wherein

the EPMC is configured to intercept a command to commence execution of code of a script at a workload;

the ACP engine is configured to determine, in response to the interception of the command by the EPMC, whether:

(i) permissions of a user issuing the command comply with a permissions security standard;

(ii) an identifier of an interpreter supporting the script is included in an approved interpreter list;

(iii) an identifier of a selected parameter of the interpreter is included in an approved parameter list, wherein the selected parameter modifies operations performed by the interpreter and the identifier of the selected parameter is distinct from the identifier of the interpreter; and

(iv) an identifier of the script is included in an approved list of executables; and

the ACP engine is configured to allow or deny the execution of the code of the script based on the determining, thereby protecting the workload from script-based attacks.

12. The system of claim 11 wherein at least one of the identifier of the interpreter, the identifier of the selected parameter, and the identifier of the script, includes a checksum.

13. The system of claim 11 wherein at least one of the EPMC and the APC engine, is further configured to:

receive an identifier of an approved interpreter, or parameter thereof, from a vendor of the approved interpreter; and

add the identifier of the approved interpreter, or parameter thereof, to the approved interpreter list, or the approved parameter list.

14. The system of claim 11 wherein at least one of the EPMC and the APC engine, is further configured to:

receive an identifier of an approved script from a vendor of the approved script; and

add the identifier of the approved script to the approved list of executables.

15. The system of claim 11 wherein allowing or denying execution of the code of the script includes:

denying the execution of the code of the script in response to the intercepted command not being present in a list of commands known to be used by the workload at runtime.

16. The system of claim 11 wherein allowing or denying execution of the code of the script includes:

denying the execution of the code of the script in response to a process to be spawned by the script matching a process in a list of known malicious processes.

17. The system of claim 11 wherein allowing or denying execution of the code of the script includes:

denying the execution of the code of the script in response to at least one of the script, a process to be spawned by the script, and a library to be loaded during the execution of the script, including a known vulnerability.

18. The system of claim 11 wherein:

the EPMC, in response to the execution of the code of the script, is configured to intercept a given process spawned during the execution of the code of the script; and

the ACP engine is configured to:

(i) tokenize the received command;

(ii) compare tokens of the tokenized received command with entries in an allow-list database; and

(iii) based on the comparing, maintain the execution, or suspend the execution, of the code of the script, or indicate a result of the comparing to a user seeking to control execution of the script.

19. The system of claim 11 wherein:

the EPMC, in response to allowing the execution of the code of the script, is configured to intercept a library loaded during the execution of the script; and

the ACP engine, in response to (i) the library including a known vulnerability, and (ii) a disposition of the library regarding the vulnerability having not been received from a user, is configured to suspend the execution of the code of the script, or to indicate the vulnerability to a user seeking to control execution of the script.

20. A computer program product for protecting a computing workload from script-based attacks, the computer program product comprising:

one or more non-transitory computer-readable storage devices and program instructions stored on at least one of the one or more storage devices, the program instructions, when loaded and executed by a processor, cause the processor to:

receive, at a workload, a command to commence execution of code of a script;

determine whether:

(i) permissions of a user issuing the command comply with a permissions security standard;

(ii) an identifier of an interpreter supporting the script is included in an approved interpreter list;

(iii) a selected parameter of the interpreter is included in an approved parameter list, wherein the selected parameter modifies operations performed by the interpreter and the identifier of the selected parameter is distinct from the identifier of the interpreter; and

(iv) an identifier of the script is included in an approved list of executables; and

allow or deny the execution of the code of the script based on the determining, thereby protecting the workload from script-based attacks.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2022
From: GUPTA, SATYA V.
To: VIRSEC SYSTEMS, INC.
Reel/Frame 061464/0888 →
Continuity (3)
Provisional Application 63190100 · May 18, 2021
Provisional Application 63190099 · May 18, 2021
Related Publication 20220391506A1 · Dec 8, 2022
References Cited (107)
US 6321334B1 · Jerger · 2001 [cited by examiner]
US 8347267B2 · Givoni et al. · 2013 [cited by applicant]
US 9246935B2 · Lietz et al. · 2016 [cited by applicant]
US 9374390B1 · Teal · 2016 [cited by examiner]
US 9418230B2 · Archer et al. · 2016 [cited by applicant]
US 9501650B2 · Chess et al. · 2016 [cited by applicant]
US 9578060B1 · Brisebois et al. · 2017 [cited by applicant]
US 9589560B1 · Vitaladevuni et al. · 2017 [cited by applicant]
US 10116681B2 · Cornell et al. · 2018 [cited by applicant]
US 10354074B2 · Gupta · 2019 [cited by applicant]
US 10387659B1 · Youngberg et al. · 2019 [cited by applicant]
US 10395041B1 · Youngberg et al. · 2019 [cited by applicant]
US 10447730B2 · Gupta · 2019 [cited by applicant]
US 10467419B1 · Youngberg et al. · 2019 [cited by applicant]
US 10963565B1 · Xu et al. · 2021 [cited by applicant]
US 11615061B1 · Malik et al. · 2023 [cited by applicant]
US 11907378B2 · Gupta · 2024 [cited by applicant]
US 12158958B2 · Gupta et al. · 2024 [cited by applicant]
US 12282552B2 · Gupta · 2025 [cited by applicant]
US 20030074207A1 · Pace et al. · 2003 [cited by applicant]
US 20040046785A1 · Keller · 2004 [cited by applicant]
US 20050102534A1 · Wong · 2005 [cited by examiner]
US 20070199000A1 · Shekhel · 2007 [cited by examiner]
US 20080052527A1 · Siedlarz · 2008 [cited by applicant]
US 20090119769A1 · Ross et al. · 2009 [cited by applicant]
US 20130111595A1 · Amit et al. · 2013 [cited by applicant]
US 20140082735A1 · Beskrovny et al. · 2014 [cited by applicant]
US 20140082739A1 · Chess et al. · 2014 [cited by applicant]
US 20140165192A1 · Zhu et al. · 2014 [cited by applicant]
US 20150215332A1 · Curcic et al. · 2015 [cited by applicant]
US 20150261653A1 · Lachambre et al. · 2015 [cited by applicant]
US 20150309813A1 · Patel · 2015 [cited by applicant]
US 20160164891A1 · Satish et al. · 2016 [cited by applicant]
US 20160241582A1 · Boia et al. · 2016 [cited by applicant]
US 20170270303A1 · Roichman et al. · 2017 [cited by applicant]
US 20170288878A1 · Lee et al. · 2017 [cited by applicant]
US 20170353434A1 · Al-Saber et al. · 2017 [cited by applicant]
US 20180349602A1 · Johns · 2018 [cited by applicant]
US 20190138725A1 · Gupta · 2019 [cited by applicant]
US 20190286833A1 · Takumi et al. · 2019 [cited by applicant]
US 20190377877A1 · Johns · 2019 [cited by applicant]
US 20200004963A1 · Zheng et al. · 2020 [cited by applicant]
US 20200042714A1 · Gupta · 2020 [cited by applicant]
US 20200065166A1 · Myneni et al. · 2020 [cited by applicant]
US 20200097662A1 · Hufsmith et al. · 2020 [cited by applicant]
US 20200134193A1 · Youngberg et al. · 2020 [cited by applicant]
US 20200134194A1 · Youngberg et al. · 2020 [cited by applicant]
US 20200134195A1 · Youngberg et al. · 2020 [cited by applicant]
US 20200167477A1 · Ionescu et al. · 2020 [cited by applicant]
US 20200336507A1 · Lee et al. · 2020 [cited by applicant]
US 20210086089A1 · Pardeshi et al. · 2021 [cited by applicant]
US 20210099483A1 · Shukla · 2021 [cited by applicant]
US 20210160273A1 · Choi et al. · 2021 [cited by applicant]
US 20220046031A1 · Kaidi · 2022 [cited by applicant]
US 20220067174A1 · Gupta · 2022 [cited by applicant]
US 20220147635A1 · Copty et al. · 2022 [cited by applicant]
US 20220198025A1 · Gupta et al. · 2022 [cited by applicant]
US 20220207151A1 · Gupta · 2022 [cited by applicant]
US 20220210180A1 · Gupta · 2022 [cited by applicant]
US 20220214928A1 · Gupta et al. · 2022 [cited by applicant]
US 20230004652A1 · Gupta · 2023 [cited by applicant]
US 20250068726A1 · Gupta et al. · 2025 [cited by applicant]
WO 2015007166A1 · 2015 [cited by applicant]
WO 2016130372A1 · 2016 [cited by applicant]
WO 2020026228A1 · 2020 [cited by applicant]
WO 2022047245A1 · 2022 [cited by applicant]
WO 2022147474A1 · 2022 [cited by applicant]
WO 2022147478A1 · 2022 [cited by applicant]
WO 2022155685A1 · 2022 [cited by applicant]
WO 2022155687A1 · 2022 [cited by applicant]
WO 2022246436A1 · 2022 [cited by applicant]
WO 2022246437A1 · 2022 [cited by applicant]
WO 2023133586A1 · 2023 [cited by applicant]
Dizdar, A. , “Why are SAST solutions not always the best option for AST?”, Bright, Jan. 22, 2020, 10 pages. [cited by applicant]
Horvath, M., et al., “Magic Quadrant for Application Security Testing” Gartner Reprint, (33 pages) Apr. 29, 2020, 33 pages, retrieved from https://www.gartner.com/doc/reprints?id=1-1YWZKUB5&ct=200429&st=sb. [cited by applicant]
Potdar, S., “The Curious Case of False Positives in Application Security”, Security Zone, May 13, 2019, 4 pages. [cited by applicant]
QwietAI “ShiftLeft Achieves Highest Ever SAST Score on OWASP Benchmark”, Nov. 1, 2023, 7 pages, retrieved from https://qwiet.ai/news-press/shiftleft-achieves-highest-ever-sast-score-on-owasp-benchmark/. [cited by applicant]
“ATT&CK (Registered)”, The Mitre, Available online at: <https://attack.mitre.org>, Sep. 14, 2023, 1 page. [cited by applicant]
“CAPEC—Common Attack Pattern Enumeration and Classification”, (CAPEC(Trademark)), Available on https://capec.mitre.org, Jan. 2, 2022, 2 pages. [cited by applicant]
“CAPEC View: Mechanisms of Attack”, View ID: 1000, (Version 3.6), Available online https://capec.mitre.org/data/definitions/1000.html, Jan. 2, 2022, 2 pages. [cited by applicant]
“Configuration Management Database (CMDB)”, 2023, 15 pages. [cited by applicant]
“CWE View: Software Development” View ID: 699, Individual Dictionary Definition (4.6), Available on https://cwe.mitre.org/data/definitions/699.html, Jan. 2, 2022, 2 pages. [cited by applicant]
“Integrated Risk Management (IRM)”, Gartner Glossary, Available on https://www.gartner.com/en/information-technology/glossary/integrated-risk-management-irm, Jan. 2, 2022, 5 pages. [cited by applicant]
“javap—The Java Class File Disassembler”, Oracle, Java SE Documentation, Available on https://docs.oracle.com/javase/7/docs/technotes/tools/windows/javap.html, Jan. 2, 2022, 3 pages. [cited by applicant]
“The Shadow Brokers”, Wikipedia, Available on https://en.wikipedia.org/wiki/The_Shadow_Brokers, Jan. 2, 2022, 8 pages. [cited by applicant]
“Welcome to YARA's documentation-yara 4.3.2 documentation” Available online at: <https://yara.readthedocs.io/en/stable/>, retrieved on Sep. 14, 2023, 4 pages. [cited by applicant]
“Windows Print Spooler Remote Code Execution Vulnerability”, Security Vulnerability, CVE-2021-34527, Available on https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527#title, Jun. 13, 2023, 1 page. [cited by applicant]
Caputo, D., et al: “Droids in Disarray: Detecting Frame Confusion in Hybrid Android Apps”, Jun. 11, 2019 (Jun. 11, 2019), Advances in Databases and Information Systems; [Lecture Notes in Computer Science; Lect.Notes Com… [cited by applicant]
Chen et al., “Automated system change discovery and management in the cloud”, IBM Journal of Research and Development, vol. 60, No. 2-3, Mar. 1, 2016, pp. 2:1-2:10. [cited by applicant]
Chen et al., “Detecting and Identifying System Changes in the Cloud via Discovery by Example”, 2014 IEEE International Conference on Big Data, Oct. 27, 2014, pp. 90-99. [cited by applicant]
Chen, Lu., et al., “Research on Mobile Application Local Denial of Service Vulnerability Detection Technology Basec on Rule Matching”, 2019 IEEE International Conference On Energy Internet (ICEI), IEEE, May 27, 2019 (Ma… [cited by applicant]
David Stahl, “What's an RFC and what can they do for me?”, Global Knowledge, Available on https://www.globalknowledge.com/us-en/resources/resource-library/articles/whats-an-rfc-and-what-can-they-do-for-me/, Sep. 16, 200… [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US2021/048077, mailed on Dec. 20, 2021, 11 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US2021/073197, mailed on Mar. 21, 2022, 10 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US2021/073201, mailed on Apr. 7, 2022, 10 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US2022/070236, mailed on Apr. 8, 2022, 15 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US2022/070240, mailed on Apr. 7, 2022, 17 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US2022/072416, mailed on Sep. 8, 2022, 13 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US2022/072417, mailed on Sep. 8, 2022, 15 pages. [cited by applicant]
Johns, M., et al., “XSSDS: Server-Side Detection of Cross-Site Scripting Attacks”, Computer Security Applications Conference, 2008. Acsac, Dec. 8, 2008, pp. 335-344. [cited by applicant]
Koutroumpouchos, K., et al., “ObjectMap: detecting insecure object deserialization”, PCI '19: Proceedings of the 23rd Pan-Hellenic Conference on Informatics, Nov. 28, 2019, pp. 67-72. [cited by applicant]
Prevelakis et al., “Sandboxing Applications”, USENIX, The Advanced Computing Systems Association, Feb. 25, 2019, pp. 1-9. [cited by applicant]
Secure execution of privileged scripts ED-Darl Kuhn, IP.Com, IP.Com Inc., West Henrietta, Sep. 18, 2009, XP013134389. [cited by applicant]
Sun, F., et al., “Client-Side Detection of XSS Worms by Monitoring Payload Propagation”, Advances In Databases And Information Systems, Sep. 21, 2009, pp. 539-554. [cited by applicant]
Xia, M. et al: “Effective Real-Time Android Application Auditing”, 2015 IEEE Symposium On Security and Privacy, IEEE, May 17, 2015 (May 17, 2015), pp. 899-914. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US2023/060379, mailed on Apr. 19, 2023, 15 pages. [cited by applicant]
Yang Ji, “Efficient and refinable attack investigation,” A Dissertation Presented to The Academic Faculty, Georgia Institute of Technology, Dec. 2019, pp. 123. [cited by applicant]
Cited By (1)
US 12,748,850