IP Library › Granted Patent US 11,481,487
Granted Patent B2
US 11,481,487 · App. 16/504,464 · Granted Oct 25, 2022

System and method of detecting file system modifications via multi-layer file system state

Inventors: Michael Halcrow (Redmond, WA); Thomas Garnier (Kirkland, WA)
Assignee: Google LLC
G06F21/554G06F16/1734G06F21/566
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,481,487
App. No.
16/504,464
Granted
Oct 25, 2022
Kind
B2
Abstract

The technology provides for a threat detection system. In this regard, the system may be configured to output file states of a multi-layer file system. For instance, the system may determine, based on the file states for a file, one or more layers of the multi-layer file system in which one or more objects corresponding to the file can be found. Based on the one or more objects corresponding to the file, the system may detect a potential threat. The system may then take an action in response to the potential threat.

Claims (72)

1. A method, comprising:

outputting, by one or more processors, file states for a file;

determining, by the one or more processors, based on the file states for the file, that one or more layers of a multi-layer file system store one or more objects corresponding to the file;

determining, by the one or more processors, that an object corresponding to the file, found in a modifiable image in an upper layer of the multi-layer file system, contains modifications to an object corresponding to the file, found in a base image in a lower layer of the multi-layer file system, by comparing the object corresponding to the file found in the modifiable image in the upper layer with the object corresponding to the file found in the base image in the lower layer;

detecting, by the one or more processors, a potential threat to the multi-layer file system based on determining that the object corresponding to the file found in the modifiable image in the upper layer, contains modifications to the object corresponding to the file found in the base image in the lower layer; and

taking an action in response to the potential threat.

2. The method of claim 1 , further comprising:

determining that none of the one or more objects corresponding to the file is found in a base image in a lower layer of the multi-layer file system,

wherein detecting the potential threat is further based on determining that none of the one or more objects corresponding to the file is found in the base image.

3. The method of claim 2 , further comprising:

creating the base image,

wherein detecting the potential threat is further based on determining that the file states indicate that the file was created after the base image.

4. The method of claim 2 , further comprising:

constructing one or more modifiable images in an upper layer of the multi-layer file system so that the one or more modifiable images contain modifications to the base image made during a runtime of an application,

wherein detecting the potential threat is further based on determining that the file states indicate that the file was created during the runtime of the application.

5. The method of claim 2 , further comprising:

constructing one or more modifiable images in an upper layer of the multi-layer file system so that the one or more modifiable images contain modifications to the base image made during an instance of a container running an application,

wherein detecting the potential threat is further based on determining that the file states indicate that the file was created during the instance of the container.

6. The method of claim 1 , further comprising:

determining whether the file is an executable binary,

wherein detecting the potential threat is further based on determining that the file is an executable binary.

7. The method of claim 1 , further comprising:

determining whether the file is a library file,

wherein detecting the potential threat is further based on determining that the file is a library file.

8. The method of claim 1 , further comprising:

determining whether the file is a script,

wherein detecting the potential threat is further based on determining that the file is a script.

9. The method of claim 1 , further comprising:

determining whether a process involving the file causes a usage of processing resources to meet a threshold value,

wherein detecting the potential threat is further based on determining that the usage of processing resources meeting the threshold value.

10. The method of claim 1 , further comprising:

determining whether the file is stored in a hard disk,

wherein detecting the potential threat is further based on the file not being stored in a hard disk.

11. The method of claim 1 , wherein taking an action in response to the potential threat includes:

generating a notification based on the potential threat; and

outputting the notification to a user interface.

12. The method of claim 11 , further comprising:

assigning a first confidence score to the potential threat based on the determination based on the file states;

assigning one or more additional confidence scores to the potential threat based on one or more additional factors indicative of a threat; and

determining that a total confidence score including the first confidence score and the one or more additional confidence scores meets a threshold level,

wherein generating the notification is further based on the total confidence score meeting the threshold level.

13. The method of claim 11 , further comprising:

determining a type of the potential threat,

wherein the notification further includes the type of the potential threat.

14. The method of claim 11 , further comprising:

identifying a container in which the potential threat is detected,

wherein the notification further includes an identity of the container.

15. A distributed computing system, comprising:

one or more processors configured to:

provide a guest operating system (OS), the guest OS configured to:

output file states for a file as events;

provide a threat detection service, the threat detection service configured to:

receive the events including the file states;

determine, based on the file states for the file, that one or more layers of a multi-layer file system store one or more objects corresponding to the file;

determine that an object corresponding to the file, found in a modifiable image in an upper layer of the multi-layer file system, contains modifications to an object corresponding to the file, found in a base image in a lower layer of the multi-layer file system, by comparing the object corresponding to the file found in the modifiable image in the upper layer with the object corresponding to the file found in the base image in the lower layer;

detect a potential threat to the multi-layer file system based on determining that the object corresponding to the file found in the modifiable image in the upper layer contains modifications to the object corresponding to the file found in the base image in the lower layer; and

generate findings on the potential threat.

16. The system of claim 15 , wherein the threat detection service is further configured to:

determine that none of the one or more objects corresponding to the file is found in a base image in a lower layer of the multi-layer file system,

wherein detecting the potential threat is further based on determining that none of the one or more objects corresponding to the file is found in the base image.

17. The system of claim 15 , wherein the threat detection service includes a plurality of detectors, the plurality of detectors each configured to analyze events involving a specific type of file.

18. The system of claim 15 , wherein the one or more processors are further configured to:

provide a security center, the security center configured to:

receive, from the threat detection service, the findings on the potential threat; and

generate a notification based on the findings.

19. A method, comprising:

outputting, by one or more processors, file states for a file;

determining, by the one or more processors, based on the file states for the file, that one or more layers of a multi-layer file system store one or more objects corresponding to the file;

determining, by the one or more processors, that an object corresponding to the file, found in a modifiable image in an upper layer of the multi-layer file system, does not have a corresponding object, found in a base image in a lower layer of the multi-layer file system;

detecting, by the one or more processors, a potential threat to the multi-layer file system based on determining that the object corresponding to the file found in the modifiable image in the upper layer does not have a corresponding object found in the base image in the lower layer; and

taking an action in response to the potential threat.

20. The method of claim 1 , further comprising retrieving modified portions from the object found in the upper layer and retrieving unmodified portions from the object found in the lower layer.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2019
From: HALCROW, MICHAEL; GARNIER, THOMAS
To: GOOGLE LLC
Reel/Frame 049698/0465 →
Continuity (1)
Related Publication 20210012000A1 · Jan 14, 2021
Cited By (2)
US 12,332,995 US 12,425,434