IP Library Granted Patent US 12,273,375
Granted Patent B2
US 12,273,375 · App. 18/147,478 · Granted Apr 8, 2025

Detection of and protection from malware and steganography

Inventors: Stewart P. MacLeod (Woodinville, WA); Robert Pike (Woodinville, WA)
Assignee: Cyemptive Technologies, Inc.
H04L63/145G06F11/2038G06F21/554G06F21/566H04L63/0263H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,375
App. No.
18/147,478
Granted
Apr 8, 2025
Kind
B2
Abstract

A method for real-time detection of and protection from steganography in a kernel mode comprises detecting transmission of a file via a firewall, an operating system, or an e-mail system. A size of the file is determined. From a file system, a stored filesize of the file is retrieved. The determined size of the file is compared to the stored filesize of the file. Responsive to the determined size of the file being larger than the stored filesize of the file, steganography detection analytics are executed on the file. Responsive to the steganography detection analytics indicating presence of steganography in the file, a steganography remediation action is executed, and information is transmitted describing the steganography to a client device.

Claims (72)

1. A method for real-time detection of and protection from steganography in a kernel mode, comprising:

receiving a file at a managed node;

storing the received file in a file system of the managed node;

determining a size of the received file by retrieving size data from a plurality of sections within the received file;

retrieving a filesize value corresponding to the received file by accessing the filesize value from a source in the file system other than the stored file;

comparing the determined size of the received file to the stored filesize value of the received file;

determining, based on the comparison, that the determined size of the received file is different from the stored filesize value of the received file;

executing, responsive to determining that the determined size of the received file is greater than the stored filesize value of the received file, steganography detection analytics on the received file;

executing a steganography remediation action based on the steganography detection analytics; and

transmitting information describing the steganography remediation action to a client device.

2. The method of claim 1 , wherein determining a size of the received file comprises:

identifying the plurality of sections associated with the received file; and

summing a size of each section of the plurality of sections.

3. The method of claim 2 , wherein identifying the plurality of sections associated with the received file comprises:

obtaining a pointer to a section header for the received file.

4. The method of claim 3 , wherein obtaining the pointer to the section header comprises:

opening the received file using a filename or path for the received file.

5. The method of claim 3 , wherein obtaining the pointer to the section header comprises:

retrieving a magic number from the section header; and

determining whether the magic number matches a file system signature for the file.

6. The method of claim 1 , wherein executing of the steganography detection analytics on the received file comprises:

identifying an appended payload in the received file;

analyzing the appended payload to determine a file format of the appended payload; and

executing the steganography detection analytics based on the file format of the appended payload.

7. The method of claim 1 , wherein executing of the steganography detection analytics on the received file comprises:

identifying an appended payload in the received file; and

performing one or more of Monte Carlo approximation, entropy determination, serial coefficient analysis, arithmetic mean determination, Chi-Square determination, and standard deviation determination to determine whether data within the appended payload is encrypted.

8. The method of claim 1 , wherein executing of the steganography detection analytics on the received file comprises:

identifying an appended payload in the received file; and

identifying presence of unauthorized data within the appended payload.

9. The method of claim 1 , wherein executing of the steganography detection analytics on the received file comprises:

identifying an appended payload in the received file; and

identifying presence of assembly level or machine level instructions within the appended payload.

10. The method of claim 1 , wherein executing of the steganography remediation action comprises:

terminating processing and transmission of the received file; and

isolating the received file.

11. A non-transitory computer-readable medium storing instructions for real-time detection of and protection from steganography in a kernel mode, wherein the instructions, when executed by a processor, cause the processor to:

receive a file at a managed node;

store the received file in a file system of the managed node;

determine a size of the received file by retrieving size data from a plurality of sections within the received file;

retrieve a filesize value corresponding to the received file by accessing the filesize value from a source in the file system other than the stored file;

compare the determined size of the received file to the stored filesize value of the received file;

determine, based on the comparison, that the determined size of the received file is different from the stored filesize value of the received file;

execute, responsive to determining that the determined size of the received file is greater than the stored filesize value of the received file, steganography detection analytics on the received file;

execute a steganography remediation action based on the steganography detection analytics; and

transmit information describing the steganography remediation action to a client device.

12. The computer-readable medium of claim 11 , wherein the instructions for determining a size of the received file comprise instructions that cause a processor to:

identify the plurality of sections associated with the received file; and

sum a size of each section of the plurality of sections.

13. The computer-readable medium of claim 12 , wherein the instructions for identifying the plurality of sections associated with the received file comprise instructions that cause a processor to:

obtain a pointer to a section header for the received file.

14. The computer-readable medium of claim 13 , wherein the instructions for obtaining the pointer to the section header comprise instructions that cause a processor to:

open the received file using a filename or path for the received file.

15. The computer-readable medium of claim 13 , wherein the instructions for obtaining the pointer to the section header comprise instructions that cause a processor to:

retrieve a magic number from the section header; and

determine whether the magic number matches a file system signature for the file.

16. The computer-readable medium of claim 11 , wherein the instructions for executing of the steganography detection analytics on the received file comprise instructions that cause a processor to:

identify an appended payload in the received file;

analyze the appended payload to determine a file format of the appended payload; and

execute the steganography detection analytics based on the file format of the appended payload.

17. The computer-readable medium of claim 11 , wherein the instructions for executing of the steganography detection analytics on the received file comprise instructions that cause a processor to:

identify an appended payload in the received file; and

perform one or more of Monte Carlo approximation, entropy determination, serial coefficient analysis, arithmetic mean determination, Chi-Square determination, and standard deviation determination to determine whether data within the appended payload is encrypted.

18. The computer-readable medium of claim 11 , wherein the instructions for executing of the steganography detection analytics on the received file comprise instructions that cause a processor to:

identify an appended payload in the received file; and

identify presence of unauthorized data within the appended payload.

19. The computer-readable medium of claim 11 , wherein the instructions for executing of the steganography detection analytics on the received file comprise instructions that cause a processor to:

identify an appended payload in the received file; and

identify presence of assembly level or machine level instructions within the appended payload.

20. The computer-readable medium of claim 11 , wherein the instructions for executing of the steganography remediation action comprise instructions that cause a processor to:

terminate processing and transmission of the received file; and

isolate the received file.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 3, 2023
From: MACLEOD, STEWART P.; PIKE, ROBERT
To: CYEMPTIVE TECHNOLOGIES, INC.
Reel/Frame 062257/0126 →
Continuity (3)
Continuation 15993426 · May 30, 2018
Provisional Application 62512659 · May 30, 2017
Related Publication 20230231872A1 · Jul 20, 2023
References Cited (41)
US 5649095A · Cozza · 1997 [cited by applicant]
US 7441153B1 · Chitre · 2008 [cited by examiner]
US 8069484B2 · McMillan et al. · 2011 [cited by applicant]
US 8621628B2 · Zeitlin et al. · 2013 [cited by applicant]
US 8650638B2 · Ma et al. · 2014 [cited by applicant]
US 9386034B2 · Cochenour · 2016 [cited by applicant]
US 20090038011A1 · Nadathur · 2009 [cited by applicant]
US 20090044024A1 · Oberheide et al. · 2009 [cited by applicant]
US 20090158430A1 · Borders · 2009 [cited by examiner]
US 20110209219A1 · Zeitlin et al. · 2011 [cited by applicant]
US 20120255017A1 · Sallam · 2012 [cited by applicant]
US 20150026464A1 · Hanner, Sr. · 2015 [cited by examiner]
US 20150058987A1 · Thure et al. · 2015 [cited by applicant]
US 20150172300A1 · Cochenour · 2015 [cited by applicant]
US 20150244679A1 · Diehl et al. · 2015 [cited by applicant]
US 20160381054A1 · Agaian · 2016 [cited by examiner]
US 20170032123A1 · Carson · 2017 [cited by applicant]
US 20170091482A1 · Sarin et al. · 2017 [cited by applicant]
US 20200193023A1 · Olarig et al. · 2020 [cited by applicant]
CN 102646173A · 2012 [cited by applicant]
CN 103116724A · 2013 [cited by applicant]
CN 103679031A · 2014 [cited by applicant]
JP 5996145B1 · 2016 [cited by applicant]
JP 2017068822A · 2017 [cited by applicant]
Canadian Intellectual Property Administration, Office Action, Canadian Patent Application No. 3,065,306, Jun. 20, 2023, 4 pages. [cited by applicant]
European Patent Office, Extended European Search Report, European Patent Application No. 18809684.6, Jan. 28, 2021, 8 pages. [cited by applicant]
Intellectual Property India, First Examination Report, Indian Patent Application No. 201947049721, May 13, 2021, 8 pages. [cited by applicant]
Japan Patent Office, Office Action, Japanese Patent Application No. 2019-566622, Sep. 28, 2021, 9 pages. [cited by applicant]
PCT International Search Report and Written Opinion, PCT Application No. PCT/US18/35205, Sep. 20, 2018, 19 pages. [cited by applicant]
PCT Invitation to Pay Additional Fees, PCT Application No. PCT/US18/35205, Jul. 23, 2018, 2 pages. [cited by applicant]
Ruo, A. et al. “An Implementation of Secure Access Control on Windows OS Using Filter Driver,” [cited by applicant]
“Towards Generic Ransomware Detection,” Objective-See, Apr. 20, 2016, 25 pages [Online] [Retrieved on Jul. 24, 2018] Retrieved from the Internet <URL:https://objective-see.com/blog/blog0x0F.html>. [cited by applicant]
United States Office Action, U.S. Appl. No. 15/993,423, Aug. 13, 2020, 25 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 15/993,423, Apr. 29, 2020, 26 pages. [cited by applicant]
Zeltser, L., “How Would You Detect and Impede Ransomware on an Endpoint?” Updated Oct. 31, 2017, 1995-2018, 6 pages, [Online] [Retrieved on Jul. 24, 2018] Retrieved from the Internet <URL:https://zeltser.com/detect-impe… [cited by applicant]
China National Intellectual Property Administration, Office Action, Chinese Patent Application No. 201880049047.3, Mar. 31, 2023, 28 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 15/993,426, Mar. 22, 2022, 21 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 15/993,426, Feb. 2, 2022, 19 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 15/993,426, Sep. 15, 2021, 17 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 15/993,426, Jan. 6, 2021, 18 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 15/993,426, May 15, 2020, 13 pages. [cited by applicant]