IP Library Granted Patent US 12,500,905
Granted Patent B2
US 12,500,905 · App. 18/615,543 · Granted Dec 16, 2025

Process tree and tags

Inventor: Brandon M. Edwards (Brooklyn, NY)
Assignee: Capsule8, Inc.
H04L63/1416G06F11/0793G06F11/3093G06F11/327G06F11/3636G06F21/552G06F21/554G06F21/577H04L63/1425H04L63/1433G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,500,905
App. No.
18/615,543
Granted
Dec 16, 2025
Kind
B2
Abstract

Information associated with a process is received. At least a portion of the received information is used to modify a Process Tree. Modifying the Process Tree includes at least one of: (1) adding a Tag to the Process Tree and (2) modifying a Tag in the Process Tree. An Alert is generated based at least in part in response to determining that a Strategy has been matched.

Claims (43)

1 . A computer program product comprising computer executable code embodied in in a non-transitory computer readable storage medium that, when executing on one or more processors, causes the one or more processors to perform steps comprising:

storing a process tree that includes a plurality of processes executing on a computing system;

storing one or more tags for the plurality of processes in the process tree, wherein:

each tag contains state information about an associated one of the plurality of processes, and

each tag propagates within the process tree according to an inheritance property that identifies the tag as at least one of inheritable, not inheritable, or inherited;

applying a detection strategy based on data in the process tree to detect events on the computing system indicative of a malicious behavior;

in response to a detection of the malicious behavior on the computing system with the detection strategy, generating an alert for one of the plurality of processes in the process tree; and

propagating the alert as an additional tag in the process tree based on a corresponding inheritance property for the alert.

2 . The computer program product of claim 1 , wherein the computing system is at least one of a workload instance, a server, a legacy system, a hardware computing system, a cloud-hosted workload instance, and a node.

3 . The computer program product of claim 1 , wherein the alert indicates that an insecure privilege escalation has occurred.

4 . The computer program product of claim 1 , wherein the alert indicates an original user that is different from a user currently associated with the one of the plurality of processes.

5 . The computer program product of claim 1 , wherein the alert indicates a propagation of an interactive shell in the process tree.

6 . The computer program product of claim 1 , wherein the detection strategy is based on one of the one or more tags indicating an interactive shell use.

7 . The computer program product of claim 1 , wherein the detection strategy is based on information received from a sensor executing in a user space of the computing system.

8 . The computer program product of claim 1 , further comprising code that performs the steps of:

receiving information associated with the one of the plurality of processes; and

modifying the process tree based on the information.

9 . The computer program product of claim 8 , wherein modifying the process tree includes adding a new tag to the process tree.

10 . The computer program product of claim 8 , wherein modifying the process tree includes modifying one of the one or more tags for processes in the process tree.

11 . The computer program product of claim 1 , further comprising code that performs the step of, in response to the detection of the malicious behavior on the computing system, initiating a remedial action on the computing system.

12 . A method comprising:

storing a process tree that includes a plurality of processes executing on a computing system;

storing one or more tags for the plurality of processes in the process tree, wherein:

each tag contains state information about an associated one of the plurality of processes, and

each tag propagates within the process tree according to an inheritance property that identifies the tag as at least one of inheritable, not inheritable, or inherited;

applying a detection strategy to detect events on the computing system indicative of a malicious behavior;

in response to a detection of the malicious behavior on the computing system with the detection strategy, generating an alert for one of the plurality of processes; and

propagating the alert as an additional tag in the process tree based on a corresponding inheritance property for the alert.

13 . The method of claim 12 , wherein the detection strategy is based on data from the process tree.

14 . The method of claim 12 , wherein the computing system is at least one of a workload instance, a server, a legacy system, a hardware computing system, a cloud-hosted workload instance, and a node.

15 . The method of claim 12 , wherein the alert indicates that an insecure privilege escalation has occurred.

16 . The method of claim 12 , wherein the alert indicates an original user that is different from a user currently associated with the one of the plurality of processes.

17 . The method of claim 12 , wherein the detection strategy is based on one of the one or more tags indicating an interactive shell use.

18 . The method of claim 12 , wherein the detection strategy is based on information received from a sensor executing in a user space of the computing system.

19 . The method of claim 12 , further comprising, in response to the detection of the malicious behavior on the computing system, initiating a remedial action on the computing system.

20 . A system, the system comprising a processor configured by computer executable code stored in a memory to perform steps comprising:

storing a process tree that includes a plurality of processes executing on a computing system;

storing one or more tags for the plurality of processes in the process tree, wherein:

each tag contains state information about an associated one of the plurality of processes, and

each tag propagates within the process tree according to an inheritance property that identifies the tag as at least one of inheritable, not inheritable, or inherited;

applying a detection strategy to detect events on the computing system indicative of a malicious behavior;

in response to a detection of the malicious behavior on the computing system with the detection strategy, generating an alert for one of the plurality of processes; and

propagating the alert as an additional tag in the process tree based on a corresponding inheritance property for the alert.

Assignments (3)
MERGER Recorded Nov 19, 2025
From: CAPSULE8, LLC
To: SOPHOS INC.
Reel/Frame 072966/0801 →
CHANGE OF NAME Recorded Nov 19, 2025
From: CAPSULE8, INC.
To: CAPSULE8, LLC
Reel/Frame 073333/0484 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2024
From: EDWARDS, BRANDON M.
To: CAPSULE8, INC.
Reel/Frame 066898/0300 →
Continuity (5)
Continuation 17336128 · Jun 1, 2021
Continuation 16698918 · Nov 27, 2019
Provisional Application 62825737 · Mar 28, 2019
Provisional Application 62773892 · Nov 30, 2018
Related Publication 20240259404A1 · Aug 1, 2024
References Cited (94)
US 4931931A · Syre et al. · 1990 [cited by applicant]
US 5991856A · Spilo et al. · 1999 [cited by applicant]
US 7315826B1 · Guheen et al. · 2008 [cited by applicant]
US 7725433B1 · Labrie · 2010 [cited by applicant]
US 8181244B2 · Boney · 2012 [cited by applicant]
US 8201243B2 · Boney · 2012 [cited by applicant]
US 8418250B2 · Morris et al. · 2013 [cited by applicant]
US 8719932B2 · Boney · 2014 [cited by applicant]
US 8726389B2 · Morris et al. · 2014 [cited by applicant]
US 8763123B2 · Morris et al. · 2014 [cited by applicant]
US 8856505B2 · Schneider · 2014 [cited by applicant]
US 9413721B2 · Morris et al. · 2016 [cited by applicant]
US 9578045B2 · Jaroch et al. · 2017 [cited by applicant]
US 9659182B1 · Roundy et al. · 2017 [cited by applicant]
US 10033759B1 · Kabra et al. · 2018 [cited by applicant]
US 10169571B1 · Attfield et al. · 2019 [cited by applicant]
US 10257224B2 · Jaroch et al. · 2019 [cited by applicant]
US 10284591B2 · Giuliani et al. · 2019 [cited by applicant]
US 10430591B1 · Pratt et al. · 2019 [cited by applicant]
US 10467407B2 · Frank et al. · 2019 [cited by applicant]
US 10599844B2 · Schmidtler et al. · 2020 [cited by applicant]
US 10685115B1 · Lieberman et al. · 2020 [cited by applicant]
US 11409869B2 · Schmidtler et al. · 2022 [cited by applicant]
US 20030023956A1 · Dulberg et al. · 2003 [cited by applicant]
US 20030149895A1 · Choo et al. · 2003 [cited by applicant]
US 20040025015A1 · Satterlee et al. · 2004 [cited by applicant]
US 20040162061A1 · Abrol et al. · 2004 [cited by applicant]
US 20040168173A1 · Cohen et al. · 2004 [cited by applicant]
US 20050076237A1 · Cohen · 2005 [cited by examiner]
US 20050132232A1 · Sima · 2005 [cited by applicant]
US 20050278706A1 · Garza et al. · 2005 [cited by applicant]
US 20060230207A1 · Finkler · 2006 [cited by applicant]
US 20070055711A1 · Polyakov et al. · 2007 [cited by applicant]
US 20070078915A1 · Gassoway · 2007 [cited by applicant]
US 20070204257A1 · Kinno et al. · 2007 [cited by applicant]
US 20080034430A1 · Burtscher · 2008 [cited by applicant]
US 20090116651A1 · Liang et al. · 2009 [cited by applicant]
US 20090216869A1 · Kennedy · 2009 [cited by applicant]
US 20090271863A1 · Govindavajhala et al. · 2009 [cited by applicant]
US 20100031360A1 · Seshadri et al. · 2010 [cited by applicant]
US 20110219449A1 · St et al. · 2011 [cited by applicant]
US 20120204193A1 · Nethercutt · 2012 [cited by applicant]
US 20120254993A1 · Sallam · 2012 [cited by applicant]
US 20120324575A1 · Choi · 2012 [cited by examiner]
US 20150128250A1 · Lee et al. · 2015 [cited by applicant]
US 20160042179A1 · Weingarten · 2016 [cited by examiner]
US 20160359658A1 · Yadav et al. · 2016 [cited by applicant]
US 20160378587A1 · Zhang et al. · 2016 [cited by applicant]
US 20160381032A1 · Hashmi et al. · 2016 [cited by applicant]
US 20170220795A1 · Suginaka · 2017 [cited by applicant]
US 20180060569A1 · Kim et al. · 2018 [cited by applicant]
US 20180285561A1 · Frank et al. · 2018 [cited by applicant]
US 20190138715A1 · Shukla · 2019 [cited by applicant]
US 20190180036A1 · Shukla · 2019 [cited by applicant]
US 20190243964A1 · Shukla et al. · 2019 [cited by applicant]
US 20190311115A1 · Lavi · 2019 [cited by examiner]
US 20240187423A1 · Edwards · 2024 [cited by applicant]
US 20250175475A1 · Markowsky · 2025 [cited by applicant]
CN 106713277 · 2017 [cited by applicant]
Ramaswamy, Ashwin , “Detecting Kernel Rootkits”, Masters Thesis Proposal Dartmouth Computer Science Technical Report TR2008-627 Sep. 2, 2008 , 30 pages. [cited by applicant]
Tian, Donghai et al., “An Online Approach to Defeating Return-Oriented- Programming Attacks”, Cyberspace Safety and Security: 9th International Symposium Oct. 2017 , 13 pages. [cited by applicant]
Dobel, Bjorn , “Request Tracking in DROPS”, Technische Universitat Dresden Fakultat Informatik May 30, 2006 , 91 pages. [cited by applicant]
Author Unknown, “Checking the Current TTY”, tldp.org, https://web.archive.org/web/20180103035946/https:/tldp.org/HOWTO/Bash-Prompt-HOWTO/x721.html Jan. 3, 2018 , 1 page. [cited by applicant]
Long, David , “Kprobes Event Tracing on Armv8, Linaro”, Dec. 16, 2016 , 9 pages. [cited by applicant]
Hossain, Md N et al., “Sleuth: Real-time Attack Scenario Reconstruction from COTS Audit Data”, 26th USENIX Security Symposium, ISBN 978-1-931971-40—Aug. 9, 2017 , 19 pages. [cited by applicant]
Bala, P. Manju et al., “Session Hijacking Prevention Using Magic Cookie with MAC”, Asian Journal of Electrical Science, vol. 3.No. 1 Aug. 2015 , pp. 46-49. [cited by applicant]
Goswami, Sudhanshu , “An Introduction to KProbes”, Apr. 18, 2005 , 8 pages. [cited by applicant]
Author Unknown, “11 Distributed Erlang”, erlang .org. found at http://erlang.org/documentation/doc-5.5.1 /doc/reference_manual/distributed.html Aug. 2016 , 4 pages. [cited by applicant]
Reeves, Jason et al., “Lightweight Intrusion Detection for Resource-Constrained Embedded Control Systems”, 5th International Conference Critical Infrastructure Protection (ICCIP), 10.1007/978-3-642-24864-1_3) Mar. 2011 … [cited by applicant]
Lu, Kangjie et al., “Unleashing Use-Before-Initialization Vulnerabilities in the Linux Kernel Using Targeted Stack Spraying”, Internet Society 2017 , 15 pages. [cited by applicant]
Hoole, Alexander M. , “Security Vulnerability Verification through Contract-Based Assertion Monitoring at Runtime”, University of Victoria 2016 , 220 pages. [cited by applicant]
Luhtala, Harri et al., “Instrumentation of a Linux-Based Mobile Device”, University of Oulu, Department of Electrical Engineering 2015 , 51 Pages. [cited by applicant]
Konovalov, Andrey , “Project Zero: Exploiting the Linux kernel via packet sockets”, News and Updates from the Project Zero Team at Google 2015 , 14 pages. [cited by applicant]
Kurmus, et al., “Quantifiable Run-time Kernel Attack Surface Reduction”, Detection of Intrusions and Malware, and Vulnerability Assessment, 2014, vol. 8550, ISBN : 978-3-319-08508-1 2014 , 20 pages. [cited by applicant]
Sun, Jian et al., “The Study of Data Collecting Based on Kprobe”, 2011 Fourth International Symposium on Computational Intelligence and Design 2011 , 4 pages. [cited by applicant]
Pohlack, Martin et al., “Towards Runtime Monitoring in Real-Time Systems”, Proceedings of the Eighth Real-Time Linux Workshop 2006 , 8 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 17/336,128 Non-Final Office Action mailed Mar. 31, 2023”, 18 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 17/336,128 Notice of Allowance mailed Nov. 21, 2023”, 10 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 17/348,671 Non-Final Office Action mailed Sep. 15, 2022”, 15 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 17/348,671 Notice of Allowance mailed Mar. 16, 2023”, 10 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 17/348,680 Final Office Action mailed Jun. 26, 2023”, 11 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 17/348,680 Non-Final Office Action mailed Dec. 8, 2022”, 12 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 17/348,680 Notice of Allowance mailed Aug. 30, 2024”, 6 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 18/366,195 Non-Final Office Action mailed Sep. 5, 2024”, 17 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/698,918 Notice of Allowance mailed Mar. 1, 2021”, 11 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/698,920 Final Office Action mailed Sep. 2, 2020”, 16 Pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/698,920 Non-Final Office Action mailed Nov. 18, 2020”, 17 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/698,920 Non-Final Office Action mailed Apr. 1, 2020”, 16 Pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/698,920 Notice of Allowance mailed Apr. 21, 2021”, 13 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/698,925 Final Office Action mailed Sep. 24, 2020”, 14 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/698,925 Non-Final Office Action mailed Jun. 5, 2020”, 15 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/698,925 Notice of Allowance mailed May 5, 2021”, 8 pages. [cited by applicant]
USPTO, , “U.S. Appl. No. 18/366,195 Final Office Action mailed Apr. 2, 2025”, NPL-1199 , 19 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 18/366,195 Notice of Allowance mailed Aug. 1, 2025”, 5 pages. [cited by applicant]