IP Library › Patent Application 18966334
Patent Application
App. No. 18/966,334

RULES PROCESSING SYSTEMS AND METHODS WITH JUST-IN-TIME COMPILATION FOR ENDPOINT PROTECTION IN KERNEL MODE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/966,334
Abstract

An endpoint protection system implementing a new blocking strategy allows a user to specify an arbitrary number of protection rules through a user interface. In user mode, the protection rules are compiled into a single expression tree, which is then compiled into byte code. In kernel mode, the byte code is dynamically loaded in memory (e.g., kernel space) and the assembler validates the byte code and performs a plurality of security checks, then ultimately assembles the byte code into machine code that is native to the processor. Because complex detection/protection logic is compiled in user mode, the invention allows for highly expressive and powerful protection rules. Further, because complex detection/protection logic is not manually written in kernel mode, but validated then evaluated via simple machine code instructions in the privileged mode, the invention is safer and will not slow down the entire operating system.

Claims (42)

1 . A method, comprising:

compiling, by a compiler in a user mode of an operating system on an endpoint of a computer network, a protection rule into an expression tree, the protection rule implementing a blocking strategy;

compiling, by the compiler in the user mode of the operating system, the expression tree into byte code;

loading, by an assembler on the endpoint, the byte code in a kernel mode of the operating system;

validating, by the assembler on the endpoint, the byte code in the kernel mode of the operating system, the validating comprising performing a security check on the byte code; and

assembling, by the assembler on the endpoint, the byte code into machine code for execution in the kernel mode of the operating system so as to implement the blocking strategy in the kernel mode of the operating system.

2 . The method according to claim 1 , further comprising:

responsive to an instruction received through a graphical user interface, generating a filter which implements the protection rule.

3 . The method according to claim 2 , wherein the filter is generated in a language specific to an application domain.

4 . The method according to claim 1 , wherein the protection rule is written in a language specific to an application domain.

5 . The method according to claim 1 , wherein compiling the protection rule into the expression tree comprises interpreting the protection rule using an interpreter.

6 . The method according to claim 5 , wherein the interpreter is embedded in a host application.

7 . The method according to claim 6 , wherein the host application comprises a regular expression engine.

8 . An apparatus, comprising:

a processor;

a non-transitory computer-readable medium;

an operating system having a user mode and a kernel mode; and

instructions stored on the non-transitory computer-readable medium for implementing a compiler and an assembler, the instructions when translated by the processor perform:

compiling, by the compiler in the user mode of the operating system, a protection rule into an expression tree, the protection rule implementing a blocking strategy;

compiling, by the compiler in the user mode of the operating system, the expression tree into byte code;

loading, by the assembler, the byte code in the kernel mode of the operating system;

validating, by the assembler, the byte code in the kernel mode of the operating system, the validating comprising performing a security check on the byte code; and

assembling, by the assembler, the byte code into machine code for execution in the kernel mode of the operating system so as to implement the blocking strategy in the kernel mode of the operating system.

9 . The apparatus of claim 8 , wherein the instructions when translated by the processor further perform:

responsive to an instruction received through a graphical user interface, generating a filter which implements the protection rule.

10 . The apparatus of claim 9 , wherein the filter is generated in a language specific to an application domain.

11 . The apparatus of claim 8 , wherein the protection rule is written in a language specific to an application domain.

12 . The apparatus of claim 8 , wherein compiling the protection rule into the expression tree comprises interpreting the protection rule using an interpreter.

13 . The apparatus of claim 12 , wherein the interpreter is embedded in a host application.

14 . The apparatus of claim 13 , wherein the host application comprises a regular expression engine.

15 . A computer program product comprising a non-transitory computer-readable medium storing instructions implementing a compiler and an assembler on an endpoint of a computer network, the endpoint having a processor and an operating system running in a user mode and a kernel mode, the instructions when translated by the processor perform:

compiling, by the compiler in the user mode of the operating system, a protection rule into an expression tree, the protection rule implementing a blocking strategy;

compiling, by the compiler in the user mode of the operating system, the expression tree into byte code;

loading, by the assembler, the byte code in the kernel mode of the operating system;

validating, by the assembler, the byte code in the kernel mode of the operating system, the validating comprising performing a security check on the byte code; and

assembling, by the assembler, the byte code into machine code for execution in the kernel mode of the operating system so as to implement the blocking strategy in the kernel mode of the operating system.

16 . The computer program product of claim 15 , wherein the instructions when translated by the processor further perform:

responsive to an instruction received through a graphical user interface, generating a filter which implements the protection rule.

17 . The computer program product of claim 16 , wherein the filter is generated in a language specific to an application domain.

18 . The computer program product of claim 15 , wherein the protection rule is written in a language specific to an application domain.

19 . The computer program product of claim 15 , wherein compiling the protection rule into the expression tree comprises interpreting the protection rule using an interpreter.

20 . The computer program product of claim 19 , wherein the interpreter is embedded in a regular expression engine.

Assignments (2)
MERGER Recorded Jun 23, 2026
From: OPEN TEXT HOLDINGS, INC.
To: OPEN TEXT INC.
Reel/Frame 075054/0712 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2024
From: BAILEY, MICHAEL JAMES; THERRIEN, JACOB HARRIS
To: OPEN TEXT HOLDINGS, INC.
Reel/Frame 069597/0638 →