IP Library Granted Patent US 12,489,763
Granted Patent B2
US 12,489,763 · App. 18/366,195 · Granted Dec 2, 2025

Dynamic detection strategies for kernel sensors

Inventor: Brandon M. Edwards (Brooklyn, NY)
Assignee: Capsule8, Inc.
H04L63/1416G06F11/0793G06F11/3093G06F11/327G06F11/3636G06F21/552G06F21/554G06F21/577H04L63/1425H04L63/1433G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,489,763
App. No.
18/366,195
Granted
Dec 2, 2025
Kind
B2
Abstract

Detection strategies for a node are selected and deployed based on the amount of data collection that is associated with various modes of telemetry available to the node.

Claims (44)

1 . A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for deploying strategies to detect malicious activity on an endpoint, the computer instructions configuring one or more processors to perform the steps of:

executing a sensor to monitor kernel activity on a node;

with an analytics component for the node, providing a strategy for detecting malicious behavior on the node;

providing a plurality of modes of telemetry collection for the strategy including two or more of:

a data collection tap built into a kernel subsystem,

an on-demand collection hook for exported kernel symbols, and

an on-demand collection hook for kernel function entry or return;

enumerating metadata for the sensor, the metadata including configuration information used to initialize the sensor;

selecting one of the plurality of modes of telemetry collection for the strategy based on a highest performing one of the plurality of modes of telemetry collection corresponding to the metadata for the sensor; and

applying the strategy to the one of the plurality of modes of telemetry collection to monitor for malicious behavior on the node.

2 . The computer program product of claim 1 , further comprising code that performs the step of prioritizing the strategy relative to one or more other ones of a plurality of strategies for monitoring the node based on a rate of data collection associated with the strategy on the node.

3 . The computer program product of claim 1 , wherein the data collection tap includes a tracepoint.

4 . The computer program product of claim 1 , wherein the on-demand collection hook includes a kprobe.

5 . The computer program product of claim 1 , wherein the on-demand collection hook includes a kretprobe.

6 . A method for deploying strategies to detect malicious activity on an endpoint, the method comprising:

executing a sensor to monitor kernel activity on a node;

with an analytics component for the node, providing a strategy for detecting malicious behavior on the node with data from the sensor;

providing a plurality of modes of telemetry collection for the strategy, including at least one on-demand collection hook for kernel function entry or return;

enumerating metadata for the sensor, the metadata including configuration information used to initialize the sensor;

selecting one of the plurality of modes of telemetry collection for the strategy based on a highest performing one of the plurality of modes of telemetry collection corresponding to the metadata for the sensor; and

prioritizing the strategy relative to one or more other strategies for monitoring the node based on a rate of data collection associated with the one of the plurality of modes of telemetry collection.

7 . The method of claim 6 wherein the plurality of modes include one or more of: a data collection tap built into a kernel subsystem, and an on-demand collection hook for exported kernel symbols.

8 . The method of claim 6 , wherein the strategy for detecting malicious behavior includes at least one memory protection strategy.

9 . The method of claim 6 , wherein the strategy for detecting malicious behavior includes at least one stack pivot detection strategy.

10 . The method of claim 6 , wherein the strategy for detecting malicious behavior includes at least one privilege escalation detection strategy.

11 . The method of claim 6 , wherein the strategy for detecting malicious behavior includes at least one interactive shell detection strategy.

12 . The method of claim 6 , wherein the strategy for detecting malicious behavior includes at least one of a kernel payload detection strategy and a kernel module loading detection strategy.

13 . The method of claim 6 , wherein the strategy for detecting malicious behavior includes at least one spectre-meltdown detection strategy.

14 . The method of claim 6 , wherein selecting one of the plurality of modes of telemetry collection includes selecting from among multiple methods of telemetry collection from different data sources based on data-source availability.

15 . The method of claim 6 , wherein selecting one of the plurality of modes of telemetry collection includes selecting from among multiple methods of telemetry collection depending on a kernel version or one or more build options for the node.

16 . The method of claim 6 , wherein the node includes one or more of a cloud-based workload instance, a legacy computing system, and a containerized system.

17 . The method of claim 6 , further comprising providing a resource threshold for at least one sensor process providing telemetry on the node, and limiting an execution of the sensor process when a resource usage by the sensor process exceeds the resource threshold.

18 . A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for deploying strategies to detect malicious activity on an endpoint, the computer instructions configuring one or more processors to perform the steps of:

executing a sensor to monitor kernel activity on a node;

with an analytics component for the node, providing a strategy for detecting malicious behavior on the node;

providing a plurality of modes of telemetry collection for the strategy including two or more of:

a data collection tap built into a kernel subsystem,

an on-demand collection for exported kernel symbols, and

an on-demand collection for kernel function entry or return;

enumerating metadata for the sensor, the metadata including configuration information used to initialize the sensor;

selecting one of the plurality of modes of telemetry collection for the strategy based on a highest performing one of the plurality of modes of telemetry collection corresponding to the metadata for the sensor; and

applying the strategy to the one of the plurality of modes of telemetry collection to monitor for malicious behavior on the node.

19 . The computer program product of claim 18 , further comprising code that performs the step of prioritizing the strategy relative to one or more other ones of a plurality of strategies for monitoring the node based on a rate of data collection associated with the strategy on the node.

20 . The computer program product of claim 18 , wherein the on-demand collection includes at least one of a kprobe and a kretprobe.

Assignments (3)
MERGER Recorded Nov 19, 2025
From: CAPSULE8, LLC
To: SOPHOS INC.
Reel/Frame 072966/0801 →
CHANGE OF NAME Recorded Nov 19, 2025
From: CAPSULE8, INC.
To: CAPSULE8, LLC
Reel/Frame 073333/0484 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 8, 2023
From: EDWARDS, BRANDON M.
To: CAPSULE8, INC.
Reel/Frame 064522/0001 →
Continuity (5)
Continuation 17348671 · Jun 15, 2021
Continuation 16698920 · Nov 27, 2019
Provisional Application 62825737 · Mar 28, 2019
Provisional Application 62773892 · Nov 30, 2018
Related Publication 20240187423A1 · Jun 6, 2024
References Cited (91)
US 4931931A · Syre et al. · 1990 [cited by applicant]
US 5991856A · Spilo et al. · 1999 [cited by applicant]
US 7315826B1 · Guheen · 2008 [cited by examiner]
US 7725433B1 · Labrie · 2010 [cited by examiner]
US 8181244B2 · Boney · 2012 [cited by applicant]
US 8201243B2 · Boney · 2012 [cited by applicant]
US 8418250B2 · Morris et al. · 2013 [cited by applicant]
US 8719932B2 · Boney · 2014 [cited by applicant]
US 8726389B2 · Morris et al. · 2014 [cited by applicant]
US 8763123B2 · Morris et al. · 2014 [cited by applicant]
US 8856505B2 · Schneider · 2014 [cited by applicant]
US 9413721B2 · Morris et al. · 2016 [cited by applicant]
US 9578045B2 · Jaroch et al. · 2017 [cited by applicant]
US 9659182B1 · Roundy et al. · 2017 [cited by applicant]
US 10033759B1 · Kabra et al. · 2018 [cited by applicant]
US 10169571B1 · Attfield et al. · 2019 [cited by applicant]
US 10257224B2 · Jaroch et al. · 2019 [cited by applicant]
US 10284591B2 · Giuliani et al. · 2019 [cited by applicant]
US 10430591B1 · Pratt et al. · 2019 [cited by applicant]
US 10467407B2 · Frank et al. · 2019 [cited by applicant]
US 10599844B2 · Schmidtler et al. · 2020 [cited by applicant]
US 10685115B1 · Lieberman · 2020 [cited by examiner]
US 11409869B2 · Schmidtler et al. · 2022 [cited by applicant]
US 20030023956A1 · Dulberg et al. · 2003 [cited by applicant]
US 20030149895A1 · Choo et al. · 2003 [cited by applicant]
US 20040025015A1 · Satterlee · 2004 [cited by examiner]
US 20040162061A1 · Abrol et al. · 2004 [cited by applicant]
US 20040168173A1 · Cohen et al. · 2004 [cited by applicant]
US 20050076237A1 · Cohen et al. · 2005 [cited by applicant]
US 20050132232A1 · Sima · 2005 [cited by applicant]
US 20050278706A1 · Garza et al. · 2005 [cited by applicant]
US 20060230207A1 · Finkler · 2006 [cited by applicant]
US 20070055711A1 · Polyakov et al. · 2007 [cited by applicant]
US 20070078915A1 · Gassoway · 2007 [cited by applicant]
US 20070204257A1 · Kinno et al. · 2007 [cited by applicant]
US 20080034430A1 · Burtscher · 2008 [cited by applicant]
US 20090116651A1 · Liang et al. · 2009 [cited by applicant]
US 20090216869A1 · Kennedy · 2009 [cited by applicant]
US 20090271863A1 · Govindavajhala et al. · 2009 [cited by applicant]
US 20100031360A1 · Seshadri et al. · 2010 [cited by applicant]
US 20110219449A1 · St. Neitzel et al. · 2011 [cited by applicant]
US 20120204193A1 · Nethercutt · 2012 [cited by applicant]
US 20120254993A1 · Sallam · 2012 [cited by examiner]
US 20120324575A1 · Choi et al. · 2012 [cited by applicant]
US 20150128250A1 · Lee et al. · 2015 [cited by applicant]
US 20160042179A1 · Weingarten et al. · 2016 [cited by applicant]
US 20160359658A1 · Yadav · 2016 [cited by examiner]
US 20160378587A1 · Zhang et al. · 2016 [cited by applicant]
US 20160381032A1 · Hashmi et al. · 2016 [cited by applicant]
US 20170220795A1 · Suginaka · 2017 [cited by applicant]
US 20180060569A1 · Kim et al. · 2018 [cited by applicant]
US 20180285561A1 · Frank et al. · 2018 [cited by applicant]
US 20190138715A1 · Shukla · 2019 [cited by applicant]
US 20190180036A1 · Shukla · 2019 [cited by applicant]
US 20190243964A1 · Shukla et al. · 2019 [cited by applicant]
US 20190311115A1 · Lavi et al. · 2019 [cited by applicant]
US 20240259404A1 · Edwards · 2024 [cited by applicant]
US 20250175475A1 · Markowsky · 2025 [cited by applicant]
CN 106713277 · 2017 [cited by applicant]
Ramaswamy, Ashwin , “Detecting Kernel Rootkits”, Masters Thesis Proposal Dartmouth Computer Science Technical Report TR2008-627 Sep. 2, 2008 , 30 pages. [cited by applicant]
Tian, Donghai et al., “An Online Approach to Defeating Return-Oriented-Programming Attacks”, Cyberspace Safety and Security: 9th International Symposium Oct. 2017 , 13 pages. [cited by applicant]
Dobel, Bjorn, “Request Tracking in DROPS”, Technische Universitat Dresden Fakultat Informatik May 30, 2006, 91 pages. [cited by applicant]
Author Unknown, “Checking the Current TTY”, tldp.org, https://web.archive.org/web/20180103035946/https:/tldp.org/HOWTO/Bash-Prompt-HOWTO/x721.html Jan. 3, 2018 , 1 page. [cited by applicant]
Long, David, “Kprobes Event Tracing on Armv8, Linaro”, Dec. 16, 2016, 9 pages. [cited by applicant]
Hossain, Md N. et al., “SLEUTH: Real-time Attack Scenario Reconstruction from COTS Audit Data”, 26th USENIX Security Symposium, ISBN 978-1-931971-40-9 Aug. 2017, 19 pages. [cited by applicant]
Bala, P. Manju et al., “Session Hijacking Prevention Using Magic Cookie with MAC”, Asian Journal of Electrical Science, vol. 3.No. 1 Aug. 2015, pp. 46-49. [cited by applicant]
Goswami, Sudhanshu, “An Introduction to KProbes”, Apr. 18, 2005, 8 pages. [cited by applicant]
Author Unknown, “11 Distributed Erlang”, erlang .org. found at http://erlang.org/documentation/doc-5.5.1 /doc/reference_manual/distributed.html Aug. 2016, 4 pages. [cited by applicant]
Reeves, Jason et al., “Lightweight Intrusion Detection for Resource-Constrained Embedded Control Systems”, 5th International Conference Critical Infrastructure Protection (ICCIP), 10.1007/978-3-642-24864-1_3) Mar. 2011,… [cited by applicant]
Lu, Kangjie et al., “Unleashing Use-Before-Initialization Vulnerabilities in the Linux Kernel Using Targeted Stack Spraying”, Internet Society 2017, 15 pages. [cited by applicant]
Hoole, Alexander M., “Security Vulnerability Verification through Contract-Based Assertion Monitoring at Runtime”, University of Victoria 2016, 220 pages. [cited by applicant]
Luhtala, Harri et al., “Instrumentation of a Linux-Based Mobile Device”, University of Oulu, Department of Electrical Engineering 2015, 51 Pages. [cited by applicant]
Konovalov, Andrey , “Project Zero: Exploiting the Linux kernel via packet sockets”, News and Updates from the Project Zero Team at Google 2015 , 14 pages. [cited by applicant]
Sun, Jian et al., “The Study of Data Collecting Based on Kprobe”, 2011 Fourth International Symposium on Computational Intelligence and Design 2011 , 4 pages. [cited by applicant]
Pohlack, Martin et al., “Towards Runtime Monitoring in Real-Time Systems”, Proceedings of the Eighth Real-Time Linux Workshop 2006 , 8 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 17/336,128 Non-Final Office Action mailed Mar. 31, 2023”, 18 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 17/336,128 Notice of Allowance mailed Nov. 21, 2023”, 10 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 17/348,671 Non-Final Office Action mailed Sep. 15, 2022”, 15 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 17/348,671 Notice of Allowance mailed Mar. 16, 2023”, 10 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 17/348,680 Final Office Action mailed Jun. 26, 2023”, 11 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 17/348,680 Non-Final Office Action mailed Dec. 8, 2022”, 12 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/698,918 Notice of Allowance mailed Mar. 1, 2021”, 11 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/698,920 Final Office Action mailed Sep. 2, 2020”, 16 Pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/698,920 Non- Final Office Action mailed Nov. 18, 2020”, 17 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/698,920 Non-Final Office Action mailed Apr. 1, 2020”, 16 Pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/698,920 Notice of Allowance mailed Apr. 21, 2021”, 13 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/698,925 Final Office Action mailed Sep. 24, 2020”, 14 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/698,925 Non-Final Office Action mailed Jun. 5, 2020”, 15 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/698,925 Notice of Allowance mailed May 5, 2021”, 8 pages. [cited by applicant]
Kurmus, et al., “Quantifiable Run-time Kernel Attack Surface Reduction”, Detection of Intrusions and Malware, and Vulnerability Assessment, 2014, vol. 8550, ISBN : 978-3-319-08508-1 2014 , 20 pages. [cited by applicant]
USPTO, , “U.S. Appl. No. 17/348,680 Notice of Allowance mailed Aug. 30, 2024”, , 6 pages. [cited by applicant]