IP Library › Granted Patent US 11,481,482
Granted Patent B2
US 11,481,482 · App. 16/564,597 · Granted Oct 25, 2022

Securing an application framework from shared library sideload vulnerabilities

Inventors: Varghese Paul Mookken (Bangalore, IN); Sajith Kumar Thadathil Pilakkavil (Bangalore, IN)
Assignee: McAfee, LLC
G06F21/51G06F9/44521G06F9/44563G06F21/53G06F21/54G06F21/566G06F21/57
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,481,482
App. No.
16/564,597
Granted
Oct 25, 2022
Kind
B2
Abstract

There is disclosed in one example a computing apparatus, including: a processor and a memory; an operating system; an application framework including instructions to search a target directory for one or more shared libraries and to attempt to load the one or more shared libraries if found; and an application including: a library file including a primary feature module to provide a primary feature of the application, the primary feature module structured to operate within the application framework, wherein the library file is not independently executable by the operating system; and an unmanaged executable binary to host the library file, wherein the unmanaged executable binary is not managed by the application framework, and includes hooks to intercept the application framework's attempt to load the one or more shared libraries, and to provide security services to the one or more shared libraries before permitting the application framework to attempt to load the one or more shared libraries.

Claims (30)

1. A computing apparatus, comprising:

a processor and a memory;

an operating system;

a .NET application framework including instructions to provide managed execution of a library file within an application virtual machine, and to search a target directory for one or more dynamic link libraries (DLLs) and to attempt to load the one or more DLLs if found; and

an application comprising:

a library file comprising a primary feature module to provide a primary feature of the application, the primary feature module structured to operate within the.NET framework, wherein the library file is not independently executable outside of the .NET framework; and

an unmanaged executable binary to host the library file, wherein the unmanaged executable binary is not managed by the .NET framework, and comprises hooks to intercept the .NET framework's attempt to load the one or more DLLs, and to provide a security scan of the one or more DLLs before permitting the.NET framework to attempt to load the one or more DLLs.

2. The computing apparatus of claim 1 , wherein the operating system is a Microsoft Windows operating system.

3. The computing apparatus of claim 1 , wherein the .NET application framework is an open-source implementation of a Microsoft .NET application framework.

4. The computing apparatus of claim 1 , wherein the target directory is a local directory of the unmanaged executable.

5. The computing apparatus of claim 1 , wherein the target directory is an operating system directory.

6. The computing apparatus of claim 1 , wherein the one or more shared libraries are Unix or Linux shared object libraries.

7. The computing apparatus of claim 1 , wherein the one or more shared libraries are Windows dynamic link libraries.

8. The computing apparatus of claim 7 , wherein the .NET application framework instructions are to search for the one or more shared libraries by name.

9. The computing apparatus of claim 1 , wherein the unmanaged executable binary comprises instructions to kill an instance of the unmanaged executable binary if the security scan detects a security failure.

10. The computing apparatus of claim 1 , wherein the unmanaged executable binary comprises instructions to load an interpreter of the application framework as an object according to an object model.

11. The computing apparatus of claim 10 , wherein the interpreter is a Microsoft .NET common language runtime.

12. One or more tangible, non-transitory computer-readable storage mediums having stored thereon executable instructions that, when executed by a computer processor, cause the computer processor to:

provide a main .NET library having code for a primary application feature, the main .NET library file being non-executable outside of a .NET framework, wherein the.NET framework comprises instructions provide managed execution of a library file within an application virtual machine, and to search a target directory for a list of dynamic link libraries (DLLs), and to attempt to load one or more DLLs from the list, outside a purview of the main .NET library; and

launch an unmanaged executable process and host the main .NET library on the unmanaged executable process, wherein the unmanaged executable process is independent of the .NET framework, and includes operating system hooks into an operating system to intercept the .NET framework's attempt to load the one or more DLLs, and to subject the DLLs, if found, to a security regimen, wherein the .NET framework's attempt to load a DLL is blocked if the DLL fails the security regimen.

13. The one or more tangible, non-transitory computer-readable mediums of claim 12 , wherein the operating system is a Microsoft Windows operating system.

14. The one or more tangible, non-transitory computer-readable mediums of claim 12 , wherein the target directory is a local directory of an executable object that provides the unmanaged executable process.

15. The one or more tangible, non-transitory computer-readable mediums of claim 12 , wherein the security regimen comprises an antivirus scan of the one or more DLLs.

16. The one or more tangible, non-transitory computer-readable mediums of claim 15 , wherein the security regimen further comprises terminating the unmanaged executable process if any library fails the security regimen.

17. The one or more tangible, non-transitory computer-readable mediums of claim 12 , wherein the security regimen comprises hashing a library and comparing the hash to known malicious software.

18. The one or more tangible, non-transitory computer-readable mediums of claim 12 , wherein the security regimen comprises querying a reputation cache for a reputation for a library.

19. A method of providing enhanced security to a .NET framework that provides managed execution of a library file within an application virtual machine, and searches a target directory for shared libraries by name, and attempts to load any shared libraries found, outside a purview of a main .NET process, the method comprising:

hosting the main .NET process as a library file under an unmanaged executable process, wherein the unmanaged executable process is independent of the .NET framework; and

wherein the unmanaged executable process includes operating system hooks to intercept the.NET framework's attempt to load the shared libraries within an operating system, and to subject the shared libraries, if found, to a security scan, wherein the .NET framework's attempt to load the shared libraries is blocked if a shared library fails the security scan.

20. The method of claim 19 , wherein the operating system is a Microsoft Windows operating system.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2019
From: MOOKKEN, VARGHESE PAUL; PILAKKAVIL, SAJITH KUMAR THADATHIL
To: MCAFEE, LLC
Reel/Frame 050315/0712 →
Continuity (1)
Related Publication 20210073374A1 · Mar 11, 2021
Cited By (1)
US 12,204,881