IP Library Granted Patent US 12,664,255
Granted Patent B2
US 12,664,255 · App. 18/676,573 · Granted Jun 23, 2026

Preventing EDR termination using vulnerable drivers

Inventors: Or Chechik (Rishon LeZion, IL); Ori Damari (Ramat Gan, IL); Yaron Samuel (Ramat Gan, IL)
Assignee: Palo Alto Networks, Inc.
G06F21/51G06F21/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,664,255
App. No.
18/676,573
Filed
May 29, 2024
Granted
Jun 23, 2026
Kind
B2
Art Unit
2436
USPC
726/22
Abstract

Methods, storage systems and computer program products implement embodiments of the present invention that include deploying, in a memory used by an operating system kernel of a computer, a hooked version of a syscall that is configured to modify an execution status of processes executing on the computer. Subsequent to one or more protected processes being specified, a notification of a call to the syscall from the hooked version of the syscall is received, the call requesting to change the execution status of a given process executing on the computer. Finally, upon ascertaining that the given process is one of the protected processes, execution of the syscall is inhibited.

Claims (32)

1 . A method for protecting a computer, comprising:

deploying, in a memory of the computer and used by an operating system kernel of the computer, a hooked version of a syscall that is configured to modify an execution status of processes executing on the computer;

specifying one or more protected processes belonging to a security software application executing on the computer;

receiving, from the hooked version of the syscall, a notification of a call to the syscall requesting to change the execution status of a given process executing on the computer by terminating execution of the given process, wherein the hooked version of the syscall comprises injected program instructions configured to generate the notification in response to the call to the syscall; and

in response to receiving the notification and upon ascertaining that the given process is one of the protected processes, i) inhibiting execution of the hooked version of the syscall, ii) identifying a given driver that conveyed the call to the syscall, identifying a first process that loaded the given driver to the memory, and identifying a second process that instructed the given driver to call the syscall to terminate the execution of the given process, and iii) inhibiting execution of the identified given driver, the identified first process, and the identified second process.

2 . The method according to claim 1 , wherein deploying the hooked version of the syscall comprises injecting, into the syscall, program instructions that are configured to convey the notification in response to the call to the syscall.

3 . The method according to claim 1 , wherein the syscall is configured to modify an execution status of a given process by terminating execution of the given process.

4 . The method according to claim 3 , wherein the given process comprises one or more threads, and wherein the syscall is configured to modify an execution status of a given process by terminating execution of a given thread.

5 . The method according to claim 1 , wherein the syscall is configured to modify an execution status of a given process by suspending execution of the given process.

6 . The method according to claim 3 , wherein the given process comprises one or more threads, and wherein the syscall is configured to modify an execution status of a given process by suspending execution of a given thread.

7 . The method according to claim 1 , wherein the syscall is configured to modify an execution status of a given process by closing a handle of the given process.

8 . The method according to claim 1 , wherein the syscall is configured to manipulate a registry key for a software application executing on the computer.

9 . The method according to claim 8 , wherein the software application comprises a security software application.

10 . The method according to claim 1 , further comprising inhibiting execution of the identified driver.

11 . The method according to claim 10 , wherein the memory comprises multiple drivers comprising respective load dates, and wherein identifying the given driver comprises identifying that the given driver has a most recent load date.

12 . The method according to claim 10 , and further comprising identifying a given process that loaded the driver to the memory, and inhibiting execution of the identified process.

13 . The method according to claim 10 , wherein the given driver called the syscall in response to a request the given driver received from a given process, and further comprising identifying the given process, and inhibiting execution of the given process.

14 . The method according to claim 1 , wherein the steps of deploying, specifying, receiving, ascertaining and inhibiting are performed by an endpoint agent executing on the computer.

15 . The method according to claim 1 , wherein the specified process belongs to a security software application executing on the computer.

16 . The method according to claim 15 , wherein the security software comprises an endpoint agent.

17 . A computer, comprising:

a memory; and

a processor configured:

to deploy, in the memory used by an operating system kernel of the computer, a hooked version of a syscall that is configured to modify an execution status of processes executing on the computer,

to specify one or more protected processes belonging to a security software application executing on the computer,

to receive, from the hooked version of the syscall, a notification of a call to the syscall requesting to change the execution status of a given process executing on the computer by terminating execution of the given process, wherein the hooked version of the syscall comprises injected program instructions configured to generate the notification in response to the call to the syscall, and

in response to receiving the notification and upon ascertaining that the given process is one of the protected processes, to i) inhibit execution of the hooked version of the syscall, ii) identify a given driver that conveyed the call to the syscall, identify a first process that loaded the given driver to the memory, and identify a second process that instructed the given driver to call the syscall to terminate the execution of the given process, and iii) inhibit execution of the identified given driver, the identified first process, and the identified second process.

18 . A computer software product for protecting a computer, the computer software product comprising a non-transitory computer-readable medium, in which program instructions are stored, which instructions, when read by the computer, cause the computer:

to deploy, in a memory of the computer and used by an operating system kernel of the computer, a hooked version of a syscall that is configured to modify an execution status of processes executing on the computer;

to specify one or more protected processes belonging to a security software application executing on the computer;

to receive, from the hooked version of the syscall, a notification of a call to the syscall requesting to change the execution status of a given process executing on the computer by terminating execution of the given process, wherein the hooked version of the syscall comprises injected program instructions configured to generate the notification in response to the call to the syscall; and

in response to receiving the notification and upon ascertaining that the given process is one of the protected processes, to i) inhibit execution of the hooked version of the syscall, ii) identify a given driver that conveyed the call to the syscall, identify a first process that loaded the given driver to the memory, and identify a second process that instructed the given driver to call the syscall to terminate the execution of the given process, and iii) inhibit execution of the identified given driver, the identified first process, and the identified second process.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2024
From: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
To: PALO ALTO NETWORKS INC.
Reel/Frame 068823/0886 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: CHECHIK, OR; DAMARI, ORI; SAMUEL, YARON
To: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
Reel/Frame 067546/0008 →
Continuity (1)
Related Publication 20250371130A1 · Dec 4, 2025
References Cited (93)
US H2196H · Tester · 2007 [cited by applicant]
US 7950057B1 · Kennedy · 2011 [cited by examiner]
US 8205257B1 · Satish et al. · 2012 [cited by applicant]
US 8601584B1 · Lu · 2013 [cited by examiner]
US 8640235B2 · Repasi et al. · 2014 [cited by applicant]
US 8646076B1 · Lim et al. · 2014 [cited by applicant]
US 8990944B1 · Singh et al. · 2015 [cited by applicant]
US 9659182B1 · Roundy et al. · 2017 [cited by applicant]
US 10193918B1 · Patton et al. · 2019 [cited by applicant]
US 10409981B2 · Iyengar et al. · 2019 [cited by applicant]
US 10503904B1 · Singh et al. · 2019 [cited by applicant]
US 10860718B2 · Seetharamaiah et al. · 2020 [cited by applicant]
US 11216559B1 · Gu et al. · 2022 [cited by applicant]
US 11409868B2 · Reid et al. · 2022 [cited by applicant]
US 11520886B2 · Levy et al. · 2022 [cited by applicant]
US 11886585B1 · Davis · 2024 [cited by applicant]
US 11934801B2 · Rahmani et al. · 2024 [cited by applicant]
US 12223044B1 · Jung et al. · 2025 [cited by applicant]
US 20040049693A1 · Douglas · 2004 [cited by applicant]
US 20050091558A1 · Chess et al. · 2005 [cited by applicant]
US 20060143707A1 · Song et al. · 2006 [cited by applicant]
US 20080040800A1 · Park · 2008 [cited by applicant]
US 20090049550A1 · Shevchenko · 2009 [cited by examiner]
US 20120047515A1 · Kanetomo · 2012 [cited by examiner]
US 20120255004A1 · Sallam · 2012 [cited by examiner]
US 20140115652A1 · Kapoor et al. · 2014 [cited by applicant]
US 20150213260A1 · Park · 2015 [cited by applicant]
US 20150215335A1 · Giuliani et al. · 2015 [cited by applicant]
US 20160055337A1 · El-Moussa · 2016 [cited by applicant]
US 20160232347A1 · Badishi · 2016 [cited by applicant]
US 20170180421A1 · Shieh et al. · 2017 [cited by applicant]
US 20180068115A1 · Golovkin et al. · 2018 [cited by applicant]
US 20180115577A1 · Shukla et al. · 2018 [cited by applicant]
US 20180189490A1 · Maciejak et al. · 2018 [cited by applicant]
US 20180191779A1 · Shieh et al. · 2018 [cited by applicant]
US 20180211038A1 · Breiman et al. · 2018 [cited by applicant]
US 20180248896A1 · Challita et al. · 2018 [cited by applicant]
US 20190087572A1 · Ellam et al. · 2019 [cited by applicant]
US 20190109870A1 · Bedhapudi et al. · 2019 [cited by applicant]
US 20190121978A1 · Kraemer et al. · 2019 [cited by applicant]
US 20190138727A1 · Dontov et al. · 2019 [cited by applicant]
US 20190318090A1 · Sandoval et al. · 2019 [cited by applicant]
US 20190325133A1 · Goodridge et al. · 2019 [cited by applicant]
US 20190347418A1 · Strogov et al. · 2019 [cited by applicant]
US 20200089876A1 · Aharoni et al. · 2020 [cited by applicant]
US 20200106808A1 · Schutz et al. · 2020 [cited by applicant]
US 20200183820A1 · Hebert et al. · 2020 [cited by applicant]
US 20200204589A1 · Strogov et al. · 2020 [cited by applicant]
US 20200342100A1 · Goldstein et al. · 2020 [cited by applicant]
US 20210152595A1 · Hansen et al. · 2021 [cited by applicant]
US 20220222338A1 · Gupta · 2022 [cited by applicant]
US 20220284095A1 · Ahmed · 2022 [cited by applicant]
US 20230084691A1 · Levy et al. · 2023 [cited by applicant]
CN 115033879A · 2022 [cited by applicant]
JP 2010509654A · 2010 [cited by applicant]
JP 2015141718A · 2015 [cited by applicant]
KR 20090088198A · 2009 [cited by applicant]
KR 20100078081A · 2010 [cited by applicant]
KR 20120031745A · 2012 [cited by applicant]
KR 20120126667A · 2012 [cited by applicant]
RU 2012113963A · 2013 [cited by applicant]
WO 2008056944A1 · 2008 [cited by applicant]
WO 2022109664A1 · 2022 [cited by applicant]
WO 2022248920A1 · 2022 [cited by applicant]
WO 2023133582A1 · 2023 [cited by applicant]
1 International Application # PCT/US2025/016969 Search Report dated Apr. 22, 2025. [cited by applicant]
Frohoff, “A Proof-of-Concept Tool for Generating Payloads that Exploit unsafe Java Object Deserialization,” github.com, pp. 1-3, Jul. 16, 2022, as downloaded from https://github.com/frohoff/ysoserial. [cited by applicant]
Wikipedia, “Return-oriented Programming,” pp. 1-6, last edited Mar. 31, 2020, as downloaded from https://web.archive.org/web/20200403142512/https://en.wikipedia.org/wiki/Return-oriented_programming. [cited by applicant]
McNab, “Network Security Assessment”, 2nd edition, Chapter 16 (Exploitation Frameworks), pp. 393-414, Oct. 2007. [cited by applicant]
Balakrishnan, “Understanding Java Agents,” Tutorial, pp. 1-8, Jul. 6, 2020, as downloaded from https://dzone.com/articles/java-agent-1. [cited by applicant]
Wilson, “Windows Inline Function Hooking,” Blog Entry, LRQA Nettitude, pp. 1-11, Mar. 18, 2015, as downloaded from https://blog.nettitude.com/uk/windows-inline-function-hooking. [cited by applicant]
Palo Alto Networks, “Cortex XDR,” Datasheet, pp. 1-9, year 2023. [cited by applicant]
U.S. Appl. No. 17/979,004 Office Action dated Jun. 6, 2024. [cited by applicant]
Chechik et al., U.S. Appl. No. 18/301,366, filed Apr. 17, 2023. [cited by applicant]
Chechik et al., U.S. Appl. No. 18/676,573, filed May 29, 2024. [cited by applicant]
Aharoni et al., U.S. Appl. No. 18/779,134, filed Jul. 22, 2024. [cited by applicant]
U.S. Appl. No. 17/979,004 Office Action dated Sep. 6, 2024. [cited by applicant]
AU Application # 2021447019 Office Action dated Sep. 16, 2024. [cited by applicant]
Blackberry, “Threat Spotlight: Petya-Like Ransomware is Nasty Wiper”, pp. 1-22, Nov. 7, 2017, as downloaded from https://blogs.blackberry.com/en/2017/07/threat-spotlight-petya-like-ransomware-is-nasty-wiper. [cited by applicant]
Wikipedia, “Java Virtual Machine,” pp. 1-8, last update Oct. 25, 2022. [cited by applicant]
Cristalli et al., “Trusted Execution Path for Protecting Java Applications Against Deserialization of Untrusted Data,” Proceedings, International Conference, ICB 2007—Advances in Biometrics, Springer Nature Switzerland … [cited by applicant]
Wikipedia, “Java Remote Method Invocation,” pp. 1-4, last edited Dec. 26, 2020. [cited by applicant]
Wikipedia, “Metasploit Project,” pp. 1-7, last edited Jun. 7, 2022. [cited by applicant]
Cynet, “Cobalt Strike: White Hat Hacker Powerhouse in the Wrong Hands,” pp. 1-6, last updated Jun. 27, 2022, as downloaded from https://web.archive.org/web/20220627023847/https://www.cynet.com/network-attacks/cobalt-str… [cited by applicant]
Shah, “Analyzing CVE-2017-9791: Apache Struts Vulnerability Can Lead to Remote Code Execution,”, McAfee, pp. 1-7, Jul. 19, 2017, as downloaded from https://www.mcafee.com/blogs/other-blogs/mcafee-labs/analyzing-cve-2017… [cited by applicant]
Bauman et al, “Renewable Just-In-Time Control-Flow Integrity”, Proceedings of the 26th International Symposium On Research in Attacks, Intrusions and Defenses, Oct. 16, 2023 (Oct. 16, 2023), pp. 580-594, https://dl.acm.… [cited by applicant]
PCT International Search Report and Written Opinion for international application No. PCT/US2025/035110, dated Oct. 8, 2025. [cited by applicant]
Notice of References Cited, U.S. Appl. No. 18/789,764, dated Dec. 3, 2025. [cited by applicant]
JP Office Action, Patent Application No. 2023-572867 dated Jan. 7, 2025. [cited by applicant]
JP Notice of Allowance, JP Patent Application No. 2023-572867 dated Mar. 4, 2025. [cited by applicant]
Non-final Office Action, U.S. Appl. No. 18/789,764, dated Dec. 3, 2025. [cited by applicant]
Notice of References Cited, U.S. Appl. No. 18/779,134, dated Oct. 23, 2025. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 18/779,134, dated Oct. 23, 2025. [cited by applicant]