IP Library › Granted Patent US 11,663,333
Granted Patent B2
US 11,663,333 · App. 16/990,957 · Granted May 30, 2023

Cloud-based systems and methods for detecting and removing rootkit

Inventor: Yu Wang (San Jose, CA)
Assignee: Beijing DiDi Infinity Technology and Development Co., Ltd.
G06F21/566G06F9/52G06F21/568H04L12/40G06F2209/521H04L2012/40215H04L2012/40273
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,663,333
App. No.
16/990,957
Granted
May 30, 2023
Kind
B2
Abstract

An exemplary method includes: obtaining, at one or more cloud servers, endpoint data of an endpoint computing device; based on the endpoint data, determining, by the one or more cloud servers, a plurality of script-language rules, wherein: each of the plurality of script-language rules corresponds to an atomic operation of detecting and/or removing at least one rootkit, the at least one rootkit comprises a target rootkit, and the plurality of script-language rules comprise a set of one or more rootkit rules corresponding to the target rootkit; and transmitting, by the one or more cloud servers to the endpoint computing device, the plurality of script-language rules, wherein the set of rootkit rules is executable at the endpoint computing device to detect and/or remove the target rootkit by, for each of the set of rootkit rules, executing a corresponding atomic operation.

Claims (87)

1. A computer-implemented method, comprising:

obtaining, at one or more cloud servers, endpoint data of an endpoint computing device;

based on the endpoint data, determining, by the one or more cloud servers, a plurality of script-language rules, wherein:

each of the plurality of script-language rules corresponds to an atomic operation of detecting and/or removing at least one rootkit,

the at least one rootkit comprises a target rootkit, and

the plurality of script-language rules comprise a set of one or more rootkit rules corresponding to the target rootkit; and

transmitting, by the one or more cloud servers to the endpoint computing device, the plurality of script-language rules, wherein the set of rootkit rules is executable at the endpoint computing device to detect and/or remove the target rootkit by, for each of the set of rootkit rules, executing a corresponding atomic operation.

2. The method of claim 1 , wherein the endpoint data comprises one or more of:

a driver binary file of a driver of the endpoint computing device;

information of a process of the endpoint computing device;

a version of a driver of the endpoint computing device; and

a version of an operating system of the endpoint computing device.

3. The method of claim 1 , wherein:

the at least one rootkit comprises a different target rootkit;

the plurality of script-language rules comprise a different set of one or more rootkit rules corresponding to the different target rootkit; and

the different set of rootkit rules is executable at the endpoint computing device to detect and/or remove the different target rootkit by, for each of the different set of rootkit rules, executing a corresponding atomic operation.

4. The method of claim 1 , wherein:

the set of rootkit rules comprises one or more first rules for detecting the target rootkit and one or more second rules for removing the target rootkit;

transmitting, by the one or more cloud servers to the endpoint computing device, the plurality of script-language rules comprises:

transmitting, by the one or more cloud servers, the one or more first rules to the endpoint computing device,

obtaining, by the one or more cloud servers from the endpoint computing device, a positive result of detecting the target rootkit in the endpoint computing device, and

transmitting, by the one or more cloud servers, the one or more second rules to the endpoint computing device; and

the method further comprises receiving, at the one or more cloud servers, a message of successful removal of the target rootkit from the endpoint computing device.

5. The method of claim 4 , further comprising:

storing, at the endpoint computing device, the first and second rules;

parsing, at the endpoint computing device, the first and second rules; and

detecting and removing, at the endpoint computing device, the target rootkit by executing the first and second rules, wherein the execution of the first and second rules triggers first and second rule handlers corresponding to the first and second rules to execute a plurality of atomic operations respectively corresponding to the first and second rules.

6. The method of claim 1 , wherein transmitting the plurality of script-language rules comprises:

transmitting, by the one or more cloud servers, the plurality of script-language rules to a driver module of the endpoint computing device, wherein the driver module corresponds to a hardware abstraction layer that has a privilege level no lower than a privilege level of the target rootkit.

7. The method of claim 6 , wherein the hardware abstraction layer is a kernel-mode driver or a hypervisor handler.

8. The method of claim 1 , further comprising transmitting, by the one or more cloud servers, an updated rootkit rule to the endpoint computing device to obtain an updated set of rootkit rules by updating at least one of the set of rootkit rules, wherein the updated set of rootkit rules is executable at the endpoint computing device to detect and/or remove the target rootkit by, for each of the updated set of rootkit rules, executing a corresponding atomic operation.

9. The method of claim 1 , further comprising:

determining, by the one or more cloud servers, the target rootkit based on the endpoint data;

selecting, by the one or more cloud servers from multiple rules stored in a cloud database, the plurality of script-language rules; and

generating, by the one or more cloud servers, a computer program based on the target rootkit, wherein the set of rootkit rules comprises the computer program, and the computer program is configured to trigger the corresponding atomic operation for each of the set of rootkit rules.

10. The method of claim 1 , wherein:

the endpoint computing device comprises a vehicle-based computing device and a Controlled Area Network (CAN-bus) coupled to the vehicle-based computing device;

the endpoint data comprises CAN-bus data; and

the atomic operation of detecting and/or removing the at least one rootkit comprises an atomic operation of detecting whether the target rootkit has access to the CAN-bus.

11. The method of claim 1 , wherein:

the endpoint computing device comprises a vehicle-based computing device and a Controlled Area Network (CAN-bus) coupled to the vehicle-based computing device;

the endpoint data comprises CAN-bus data; and

the set of rootkit rules is executable to detect whether the target rootkit has access to the CAN-bus based on the CAN-bus data or to block the access.

12. The method of claim 1 , wherein:

the endpoint computing device comprises a vehicle-based computing device and an infotainment system coupled to the vehicle-based computing device;

the endpoint data comprises infotainment data; and

the set of rootkit rules is executable to detect whether the target rootkit has access to the infotainment system based on the infotainment data or to block the access.

13. The method of claim 1 , wherein:

the endpoint computing device comprises a vehicle-based computing device and a telematics box coupled to the vehicle-based computing device;

the endpoint data comprises telematics data; and

the set of rootkit rules is executable to detect whether the target rootkit has access to the telematics box based on the telematics data or to block the access.

14. A non-transitory computer-readable storage medium storing instructions executable by one or more processors, wherein execution of the instructions causes the one or more processors to perform operations comprising:

obtaining, at one or more cloud servers, endpoint data of an endpoint computing device;

based on the endpoint data, determining, by the one or more cloud servers, a plurality of script-language rules, wherein:

each of the plurality of script-language rules corresponds to an atomic operation of detecting and/or removing at least one rootkit,

the at least one rootkit comprises a target rootkit, and

the plurality of script-language rules comprise a set of one or more rootkit rules corresponding to the target rootkit; and

transmitting, by the one or more cloud servers to the endpoint computing device, the plurality of script-language rules, wherein the set of rootkit rules is executable at the endpoint computing device to detect and/or remove the target rootkit by, for each of the set of rootkit rules, executing a corresponding atomic operation.

15. The non-transitory computer-readable storage medium of claim 14 , wherein the endpoint data comprises one or more of:

a driver binary file of a driver of the endpoint computing device;

information of a process of the endpoint computing device;

a version of a driver of the endpoint computing device; and

a version of an operating system of the endpoint computing device.

16. The non-transitory computer-readable storage medium of claim 14 , wherein:

the at least one rootkit comprises a different target rootkit;

the plurality of script-language rules comprise a different set of one or more rootkit rules corresponding to the different target rootkit; and

the different set of rootkit rules is executable at the endpoint computing device to detect and/or remove the different target rootkit by, for each of the different set of rootkit rules, executing a corresponding atomic operation.

17. The non-transitory computer-readable storage medium of claim 14 , wherein:

the set of rootkit rules comprises one or more first rules for detecting the target rootkit and one or more second rules for removing the target rootkit;

transmitting, by the one or more cloud servers to the endpoint computing device, the plurality of script-language rules comprises:

transmitting, by the one or more cloud servers, the one or more first rules to the endpoint computing device,

obtaining, by the one or more cloud servers from the endpoint computing device, a positive result of detecting the target rootkit in the endpoint computing device, and

transmitting, by the one or more cloud servers, the one or more second rules to the endpoint computing device; and

the operations further comprise receiving, at the one or more cloud servers, a message of successful removal of the target rootkit from the endpoint computing device.

18. The non-transitory computer-readable storage medium of claim 17 , wherein the operations further comprise:

storing, at the endpoint computing device, the first and second rules;

parsing, at the endpoint computing device, the first and second rules; and

detecting and removing, at the endpoint computing device, the target rootkit by executing the first and second rules, wherein the execution of the first and second rules triggers first and second rule handlers corresponding to the first and second rules to execute a plurality of atomic operations respectively corresponding to the first and second rules.

19. The non-transitory computer-readable storage medium of claim 14 , wherein transmitting the plurality of script-language rules comprises:

transmitting, by the one or more cloud servers, the set of rootkit rules to a driver module of the endpoint computing device, wherein the driver module corresponds to a hardware abstraction layer that has a privilege level no lower than a privilege level of the target rootkit.

20. A computer-implemented method, comprising:

transmitting, by an endpoint computing device, endpoint data to one or more cloud servers;

receiving, at the endpoint computing device from the one or more cloud servers, a plurality of script-language rules corresponding to the endpoint data, wherein:

each of the plurality of script-language rules corresponds to an atomic operation of detecting and/or removing at least one rootkit,

the at least one rootkit comprises a target rootkit, and

the plurality of script-language rules comprise a set of one or more rootkit rules corresponding to the target rootkit; and

executing, at the endpoint computing device, the set of rootkit rules to detect and/or remove the target rootkit by, for each of the set of rootkit rules, executing a corresponding atomic operation.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2020
From: WANG, YU
To: BEIJING DIDI INFINITY TECHNOLOGY AND DEVELOPMENT CO., LTD.
Reel/Frame 053463/0322 →
Continuity (1)
Related Publication 20220050900A1 · Feb 17, 2022