IP Library Granted Patent US 12,688,279
Granted Patent B2
US 12,688,279 · App. 18/634,579 · Granted Jul 21, 2026

Systems and methods for event-based application control

Inventors: Omar Jawayd Ikram (Cheshire, GB); Simon Fradkin (Cheshire, GB)
Assignee: BeyondTrust Corporation
G06F21/54G06F9/542G06F2221/033G06F2221/2101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,688,279
App. No.
18/634,579
Filed
Apr 12, 2024
Granted
Jul 21, 2026
Kind
B2
Examiner
RONI, SYED A
Art Unit
2432
USPC
726/1
Abstract

Systems and methods are disclosed for event-based application control. A system extension is configured to leverage an endpoint security Application Programing Interface (API) for monitoring event activity within operating system kernel processes. The system extension registers with the endpoint security API particular event types for which the system extension would like to receive notifications. In response to receiving notifications regarding detected events corresponding to the registered event types, the system extension determines if the event, and its corresponding process, are safe and allowable to execute. In various embodiments, the system leverages whitelists, blacklists, and rules policies for making a safeness determination regarding the event notification. The system extension transmits this determination to the operating system via the endpoint security API.

Claims (55)

1 . A method comprising:

subscribing, via a system extension executed by at least one computing device, for at least one event type with an operating system;

receiving, via the system extension, an event notification comprising metadata associated with an event, the event corresponding to one of the at least one event type;

storing, via the system extension, the event notification in a queue;

transmitting, via the system extension, the event notification to a security service;

applying, via the security service, a plurality of rules from a policy to the event notification;

receiving, via the system extension, a decision of whether to allow the event based on the policy;

instructing, via the system extension, the operating system whether to allow the event;

determining, via the system extension, that the metadata comprises blacklisted metadata; and

performing, via the system extension, an action based on the metadata comprising the blacklisted metadata.

2 . The method of claim 1 , wherein the queue comprises a plurality of stored event notifications and storing the event notification in the queue comprises adding the event notification to the plurality of stored event notifications.

3 . The method of claim 1 , further comprising instructing the operating system whether to allow the event based on the decision of whether to allow the event in response to the decision being received before predefined time threshold.

4 . The method of claim 1 , further comprising removing, via the system extension, the event notification from the queue before instructing the operating system whether to allow the event.

5 . The method of claim 1 , further comprising:

determining, via the system extension, that a predefined time threshold from receipt of the event notification has been exceeded prior to receiving the decision; and

in response to the predefined time threshold being exceeded, instructing the operating system to deny the event.

6 . The method of claim 1 , wherein the event notification is transmitted to the security service from the queue in a first in, first out order.

7 . The method of claim 1 , further comprising dynamically adding event metadata to a blacklist based on the decision of whether to allow the event.

8 . A system, comprising:

a system extension; and

at least one computing device configured to execute the system extension to:

subscribe for at least one event type with an operating system;

receive an event notification comprising metadata associated with an event, the event corresponding to one of the at least one event type;

store the event notification in a queue;

transmit the event notification to a security service;

receive a decision of whether to allow the event based on a policy, wherein the security service is configured to apply a plurality of rules from the policy to the event notification;

instruct the operating system whether to allow the event; and

perform at least one of:

1) Dynamically adding event metadata to a blacklist based on the decision of whether to allow the event, or

2) Determining that the metadata comprises blacklisted metadata; and performing an action based on the metadata comprising the blacklisted metadata.

9 . The system of claim 8 , wherein the at least one computing device is further configured to execute the system extension to generate a copy of the event notification, wherein the copy of the event notification is transmitted to the security service.

10 . The system of claim 8 , wherein the at least one computing device is further configured to execute the system extension to remove the event notification from the queue in response to receiving the decision of whether to allow the event based on the policy.

11 . The system of claim 8 , wherein the at least one computing device is further configured to execute the system extension to transmit the event notification to the security service in response to determining that neither a whitelist or the blacklist comprises the one of the at least one event type corresponding to the event notification.

12 . The system of claim 8 , wherein the event notification is transmitted to the security service from the queue in parallel with at least one other event notification.

13 . The system of claim 8 , wherein the at least one computing device is further configured to execute the system extension to instruct the operating system to generate a command to kill a process corresponding to the event.

14 . A non-transitory computer-readable medium embodying a system extension that, when executed by at least one computing device, causes the at least one computing device to:

subscribe for at least one event type with an operating system;

receive an event notification comprising metadata associated with an event, the event corresponding to one of the at least one event type;

store the event notification in a queue;

transmit the event notification to a security service;

receive a decision of whether to allow the event based on a policy, wherein the security service is configured to apply a plurality of rules from the policy to the event notification; and

instruct the operating system whether to allow the event; and

dynamically add event metadata to a blacklist based on the decision of whether to allow the event.

15 . The non-transitory computer-readable medium of claim 14 , wherein the queue is stored in a memory as at least one of: a linked list or a vector.

16 . The non-transitory computer-readable medium of claim 14 , wherein the system extension further causes the at least one computing device to compare the event notification to a white list and a black list prior to storing the event notification in the queue.

17 . A non-transitory computer-readable medium embodying a system extension that, when executed by at least one computing device, causes the at least one computing device to:

subscribe for at least one event type with an operating system;

receive an event notification comprising metadata associated with an event, the event corresponding to one of the at least one event type;

store the event notification in a queue;

transmit the event notification to a security service;

receive a decision of whether to allow the event based on a policy, wherein the security service is configured to apply a plurality of rules from the policy to the event notification; and instruct the operating system whether to allow the event;

determine that the metadata comprises blacklisted metadata; and

perform an action based on the metadata comprising the blacklisted metadata.

18 . The non-transitory computer-readable medium of claim 17 , wherein the event notification is transmitted to the security service from the queue in an order based on priority of the event.

19 . The non-transitory computer-readable medium of claim 17 , wherein the system extension further causes the at least one computing device to dynamically update a whitelist based on the decision of whether to allow the event.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2025
From: BEYONDTRUST SOFTWARE, INC.
To: BEYONDTRUST CORPORATION
Reel/Frame 073362/0293 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 25, 2024
From: IKRAM, OMAR JAWAYD; FRADKIN, SIMON
To: BEYONDTRUST SOFTWARE, INC.
Reel/Frame 068078/0243 →
Continuity (4)
Continuation 18155330 · Jan 17, 2023
Continuation 16901679 · Jun 15, 2020
Provisional Application 62860888 · Jun 13, 2019
Related Publication 20240265096A1 · Aug 8, 2024
References Cited (13)
US 6463474B1 · Fuh et al. · 2002 [cited by applicant]
US 20080066148A1 · Lim · 2008 [cited by examiner]
US 20130086146A1 · Addala · 2013 [cited by examiner]
US 20150135253A1 · Angel et al. · 2015 [cited by applicant]
US 20180004547A1 · Hayes · 2018 [cited by examiner]
US 20190124118A1 · Swafford et al. · 2019 [cited by applicant]
EP 2691908A2 · 2014 [cited by applicant]
WO 2012135192A2 · 2012 [cited by applicant]
Kotyk A., “Avoiding Kernel Development in macOS with System Extensions and DriverKit,” Apr. 2, 2020, 22 Pages. [cited by applicant]
“Microsoft Computer Dictionary,” Microsoft Corporation, 2002, Fifth Edition, pp. 433, 3 p. [cited by applicant]
Mooney N., “Santa Leaves the Kernel: A MacOS Endpoint Security Introduction and Case Study,” Duo Security, Apr. 21, 2020, 10 Pages. [cited by applicant]
Knightsc: “An example of using the libEndpointSecurity.dylib in Catalina”, Jun. 10, 2019 (Jun. 10, 2019), XP055760958, Retrieved from the Internet: URL:https://gist.github.com/mcastilho/1774c12bb8b35be5c03f6c2e268eae64/… [cited by applicant]
Combined Search and Examination Report issued by the Great Britain Intellectual Property Office on Feb. 9, 2021, in GB application No. GB2009089.0; (10 pages). [cited by applicant]