IP Library Granted Patent US 12,095,796
Granted Patent B1
US 12,095,796 · App. 18/064,835 · Granted Sep 17, 2024

Instruction-level threat assessment

Inventors: Patrice Godefroid (Mercer Island, WA); Curtis Condra (Seattle, WA); Yijou Chen (Cupertino, CA)
Assignee: LACEWORK, INC.
H04L63/1425G06F9/455G06F9/545G06F16/9024G06F16/9038G06F16/9535G06F16/9537G06F21/57H04L63/10H04L67/306H04L67/535G06F16/2456
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,095,796
App. No.
18/064,835
Filed
Dec 12, 2022
Granted
Sep 17, 2024
Kind
B1
Art Unit
2442
USPC
709/224
Abstract

Instruction-level threat assessment, including: identifying one or more probe insertion points in code of a package corresponding to one or more vulnerabilities of the package; inserting, into one or more instances of the package deployed in one or more hosts of a cloud deployment, one or more probes based on the one or more probe insertion points; and elevating a severity of a particular vulnerability in response to reaching a particular probe of the one or more probes.

Claims (30)

1. A method of instruction-level threat assessment, the method comprising:

identifying one or more probe insertion points in code of a package corresponding to one or more vulnerabilities of the package;

inserting, into one or more instances of the package deployed in one or more hosts of a cloud deployment, one or more probes based on the one or more probe insertion points, wherein inserting the one or more probes comprises inserting the one or more probes for a binary instance of the package corresponding to the one or more probe insertion points in the code of the package; and

elevating a severity of a particular vulnerability in response to reaching a particular probe of the one or more probes.

2. The method of claim 1 , wherein identifying the one or more probe insertion points comprises identifying the one or more probe insertion points based on one or more changes to the code of the package in one or more patches for the one or more vulnerabilities of the package.

3. The method of claim 1 , wherein inserting the one or more probes is performed by an agent executed in each of the one or more hosts.

4. The method of claim 3 , wherein elevating the severity of the particular vulnerability is performed in response to the agent detecting that an execution of a binary instance package has reached the particular probe.

5. The method of claim 1 , wherein identifying the one or more probe insertion points comprises:

identifying a plurality of potential probe insertion points;

determining that the plurality of potential probe insertion points share a common execution path; and

identifying, as one of the one or more probe insertion points, a single probe insertion point instead of the plurality of potential probe insertion points.

6. The method of claim 1 , further comprising terminating an execution of the package in response to reaching the particular probe of the one or more probes.

7. The method of claim 6 , wherein terminating the execution of the package is based on an exploit enabled by the particular vulnerability.

8. The method of claim 1 , wherein the one or more probe insertion points correspond to the particular vulnerability, and wherein elevating the severity of the particular vulnerability comprises elevating the severity of the particular vulnerability in response to determining that each of the one or more probe insertion points have been reached.

9. The method of claim 1 , further comprising providing an indication that the particular probe has been reached to an anomaly detection framework.

10. A computer program product for instruction-level threat assessment, the computer program product disposed on a non-transitory computer readable medium, the computer program product including computer program instructions configurable to carry out the steps of:

identifying one or more probe insertion points in code of a package corresponding to one or more vulnerabilities of the package;

inserting, into one or more instances of the package deployed in one or more hosts of a cloud deployment, one or more probes based on the one or more probe insertion points, wherein inserting the one or more probes comprises inserting the one or more probes for a binary instance of the package corresponding to the one or more probe insertion points in the code of the package; and

elevating a severity of a particular vulnerability in response to reaching a particular probe of the one or more probes.

11. The computer program product of claim 10 , wherein identifying the one or more probe insertion points comprises identifying the one or more probe insertion points based on one or more changes to the code of the package in one or more patches for the one or more vulnerabilities of the package.

12. The computer program product of claim 10 , wherein inserting the one or more probes is performed by an agent executed in each of the one or more hosts.

13. The computer program product of claim 12 , wherein elevating the severity of the particular vulnerability is performed in response to the agent detecting that an execution of a binary instance package has reached the particular probe.

14. The computer program product of claim 10 , wherein identifying the one or more probe insertion points comprises:

identifying a plurality of potential probe insertion points;

determining that the plurality of potential probe insertion points share a common execution path; and

identifying, as one of the one or more probe insertion points, a single probe insertion point instead of the plurality of potential probe insertion points.

15. The computer program product of claim 10 , wherein the steps further comprise terminating an execution of the package in response to reaching the particular probe of the one or more probes.

16. The computer program product of claim 15 , wherein terminating the execution of the package is based on an exploit enabled by the particular vulnerability.

17. The computer program product of claim 10 , wherein the one or more probe insertion points correspond to the particular vulnerability, and wherein elevating the severity of the particular vulnerability comprises elevating the severity of the particular vulnerability in response to determining that each of the one or more probe insertion points have been reached.

18. The computer program product of claim 10 , wherein the steps further comprise providing an indication that the particular probe has been reached to an anomaly detection framework.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 7, 2024
From: LACEWORK, INC.
To: FORTINET, INC.
Reel/Frame 069301/0123 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE SECOND NAME AND SIGNATURE OF THE SECOND INVENTOR PREVIOUSLY RECORDED AT REEL: 062060 FRAME: 0846. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 1, 2023
From: GODEFROID, PATRICE; CONDRA, CURTIS; CHEN, YIJOU
To: LACEWORK, INC.
Reel/Frame 063822/0209 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2022
From: GODEFROID, PATRICE; CONDRA, GEREMY; CHEN, YIJOU
To: LACEWORK, INC.
Reel/Frame 062060/0846 →
Continuity (8)
Continuation In Part 17938755 · Oct 7, 2022
Continuation In Part 17838818 · Jun 13, 2022
Continuation In Part 17504311 · Oct 18, 2021
Continuation 16665961 · Oct 28, 2019
Continuation 16134794 · Sep 18, 2018
Provisional Application 63341792 · May 13, 2022
Provisional Application 62650971 · Mar 30, 2018
Provisional Application 62590986 · Nov 27, 2017
Cited By (14)
US 12,265,607 US 12,393,719 US 12,417,822 US 12,432,218 US 12,470,565 US 12,481,487 US 12,513,172 US 12,554,847 US 12,556,570 US 12,591,423 US 12,657,282 US 12,659,345 US 12,664,289 US 12,694,150