IP Library Granted Patent US 12,462,002
Granted Patent B2
US 12,462,002 · App. 18/081,765 · Granted Nov 4, 2025

Device protection using pre-execution command interception and user authentication

Inventors: Yevgeni Gehtman (Modi'in, IL); Tomer Shachar (Beer-Sheva, IL); Maxim Balin (Gan-Yavne, IL)
Assignee: Dell Products L.P.
G06F21/31
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,462,002
App. No.
18/081,765
Granted
Nov 4, 2025
Kind
B2
Abstract

Techniques are provided for device protection using pre-execution command interception and user authentication. One method comprises obtaining, by a software entity associated with an operating system kernel of a device, a request from a user to execute a command; determining, by the software entity associated with the operating system kernel, prior to an execution of the command, whether the command is a command of a designated command type; initiating a multi-factor authentication of the user in response to determining that the command is a command of the designated command type; and initiating an execution of the at least one command based on a result of the multi-factor authentication of the user. The determination of whether the command comprises the command of the designated command type evaluates command properties and/or command criteria. The command may be compared to a protected list of commands of the designated command type.

Claims (38)

1 . A method, comprising:

obtaining, by at least one software entity associated with an operating system kernel of at least one processing device comprising a processor coupled to a memory, a request from a user to execute at least one command;

determining, by the at least one software entity associated with the operating system kernel, subsequent to the obtaining and prior to an execution of the at least one obtained command, whether the at least one obtained command is a command of at least one designated command type requiring a multi-factor authentication,

wherein the determining further comprises one or more designated command properties and one or more designated command criteria, of the at least one obtained command, that identify commands of the designated command type, wherein commands of the at least one designated command type require a multi-factor authentication of a user that submitted the respective command prior to an execution of the respective command;

initiating a multi-factor authentication of the user, following the obtaining the request from the user and prior to the execution of the at least one command, in response to determining that the at least one obtained command is a command of the at least one designated command type requiring the multi-factor authentication; and

initiating an execution of the at least one command based at least in part on a result of the multi-factor authentication of the user.

2 . The method of claim 1 , wherein the initiating the execution of the at least one command further comprises providing the at least one command to an operating system for execution.

3 . The method of claim 1 , wherein the initiating the multi-factor authentication of the user further comprises providing an authentication request to a multi-factor authentication system associated with the at least one processing device.

4 . The method of claim 1 , wherein the request from the user to execute the at least one command comprises a request to execute a software script comprising one or more commands of the at least one designated command type.

5 . The method of claim 1 , wherein the request is received during an authenticated session of a given user on the at least one processing device and wherein the multi-factor authentication of the user comprises a multi-factor authentication of the given user.

6 . The method of claim 1 , wherein the obtaining the request from the user comprises intercepting the request.

7 . The method of claim 1 , wherein the at least one command comprises one or more of a user add command to create one or more users; a command to change a password for one or more user accounts; a change mode command that changes an access mode of one or more files; a super user command that allows a first user to execute a command on behalf of a second user; a super user command to run a function as a different user; a yum command to one or more of install, update, remove and search software packages on a system; an apt command for one or more of installing, updating, removing and managing at least one packages; a zipper command to specify a compression level; a user modification command to modify one or more existing user account details; a system control command to one or more of examine and control a service manager; and a system command to pass commands to an operating system.

8 . An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the at least one processing device being configured to implement the following steps:

obtaining, by at least one software entity associated with an operating system kernel of at least one processing device comprising a processor coupled to a memory, a request from a user to execute at least one command;

determining, by the at least one software entity associated with the operating system kernel, subsequent to the obtaining and prior to an execution of the at least one obtained command, whether the at least one obtained command is a command of at least one designated command type requiring a multi-factor authentication,

wherein the determining further comprises evaluating one or more designated command properties and one or more designated command criteria, of the at least one obtained command, that identify commands of the designated command type, wherein commands of the at least one designated command type require a multi-factor authentication of a user that submitted the respective command prior to an execution of the respective command;

initiating a multi-factor authentication of the user, following the obtaining the request from the user and prior to the execution of the at least one command, in response to determining that the at least one obtained command is a command of the at least one designated command type requiring the multi-factor authentication; and

initiating an execution of the at least one command based at least in part on a result of the multi-factor authentication of the user.

9 . The apparatus of claim 8 , wherein the initiating the execution of the at least one command further comprises providing the at least one command to an operating system for execution.

10 . The apparatus of claim 8 , wherein the initiating the multi-factor authentication of the user further comprises providing an authentication request to a multi-factor authentication system associated with the at least one processing device.

11 . The apparatus of claim 8 , wherein the request from the user to execute the at least one command comprises a request to execute a software script comprising one or more commands of the at least one designated command type.

12 . The apparatus of claim 8 , wherein the request is received during an authenticated session of a given user on the at least one processing device and wherein the multi-factor authentication of the user comprises a multi-factor authentication of the given user.

13 . The apparatus of claim 8 , wherein the obtaining the request from the user comprises intercepting the request.

14 . The apparatus of claim 8 , wherein the at least one command comprises one or more of a user add command to create one or more users; a command to change a password for one or more user accounts; a change mode command that changes an access mode of one or more files; a super user command that allows a first user to execute a command on behalf of a second user; a super user command to run a function as a different user; a yum command to one or more of install, update, remove and search software packages on a system; an apt command for one or more of installing, updating, removing and managing at least one packages; a zipper command to specify a compression level; a user modification command to modify one or more existing user account details; a system control command to one or more of examine and control a service manager; and a system command to pass commands to an operating system.

15 . A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device to perform the following steps:

obtaining, by at least one software entity associated with an operating system kernel of at least one processing device comprising a processor coupled to a memory, a request from a user to execute at least one command;

determining, by the at least one software entity associated with the operating system kernel, subsequent to the obtaining and prior to an execution of the at least one obtained command, whether the at least one obtained command is a command of at least one designated command type requiring a multi-factor authentication,

wherein the determining further comprises evaluating one or more designated command properties and one or more designated command criteria, of the at least one obtained command, that identify commands of the designated command type, wherein commands of the at least one designated command type require a multi-factor authentication of a user that submitted the respective command prior to an execution of the respective command;

initiating a multi-factor authentication of the user, following the obtaining the request from the user and prior to the execution of the at least one command, in response to determining that the at least one obtained command is a command of the at least one designated command type requiring the multi-factor authentication; and

initiating an execution of the at least one command based at least in part on a result of the multi-factor authentication of the user.

16 . The non-transitory processor-readable storage medium of claim 15 , wherein the initiating the execution of the at least one command further comprises providing the at least one command to an operating system for execution.

17 . The non-transitory processor-readable storage medium of claim 15 , wherein the request from the user to execute the at least one command comprises a request to execute a software script comprising one or more commands of the at least one designated command type.

18 . The non-transitory processor-readable storage medium of claim 15 , wherein the request is received during an authenticated session of a given user on the at least one processing device and wherein the multi-factor authentication of the user comprises a multi-factor authentication of the given user.

19 . The non-transitory processor-readable storage medium of claim 15 , wherein the obtaining the request from the user comprises intercepting the request.

20 . The non-transitory processor-readable storage medium of claim 15 , wherein the at least one command comprises one or more of a user add command to create one or more users; a command to change a password for one or more user accounts; a change mode command that changes an access mode of one or more files; a super user command that allows a first user to execute a command on behalf of a second user; a super user command to run a function as a different user; a yum command to one or more of install, update, remove and search software packages on a system; an apt command for one or more of installing, updating, removing and managing at least one packages; a zipper command to specify a compression level; a user modification command to modify one or more existing user account details; a system control command to one or more of examine and control a service manager;

and a system command to pass commands to an operating system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2022
From: GEHTMAN, YEVGENI; SHACHAR, TOMER; BALIN, MAXIM
To: DELL PRODUCTS L.P.
Reel/Frame 062099/0221 →
Continuity (1)
Related Publication 20240202295A1 · Jun 20, 2024
References Cited (14)
US 7293281B1 · Moran · 2007 [cited by applicant]
US 7784088B2 · Darbha · 2010 [cited by applicant]
US 10063537B2 · Zhu · 2018 [cited by examiner]
US 11336438B2 · Atzmony · 2022 [cited by applicant]
US 20090205050A1 · Giordano · 2009 [cited by applicant]
US 20100293614A1 · Vilppola · 2010 [cited by applicant]
US 20120192275A1 · Oliver · 2012 [cited by applicant]
US 20160132670A1 · Salama · 2016 [cited by applicant]
US 20180041510A1 · Burch · 2018 [cited by examiner]
US 20220035943A1 · Jones · 2022 [cited by examiner]
US 20230252169A1 · Savir · 2023 [cited by applicant]
US 20230308460A1 · Thomas · 2023 [cited by applicant]
U.S. Appl. No. 17/958,844 entitled “Device Protection Using Pre-Execution Command Interception and Evaluation”, filed Oct. 3, 2022. [cited by applicant]
Depuy, Travis; “Adding Approval Jobs to your CI Pipeline”; Circleci Blog; published Oct. 2, 2020; hhttps://circleci.com/blog/adding-approval-jobs-to-your-ci-pipeline/; downloaded on Sep. 17, 22. [cited by applicant]