IP Library › Granted Patent US 12,197,573
Granted Patent B2
US 12,197,573 · App. 17/177,133 · Granted Jan 14, 2025

Integrated application analysis and endpoint protection

Inventors: Zhi Xu (Cupertino, CA); Elad Wexler (Givatym, IL); Asaf Weiss (Tel-Aviv, IL)
Assignee: Palo Alto Networks, Inc.
G06F21/566G06F21/50G06F21/55G06F21/554G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,197,573
App. No.
17/177,133
Granted
Jan 14, 2025
Kind
B2
Abstract

An indication of an application to be installed on a local device is received. A request is transmitted to a remote server for information associated with the application. In some cases, in response to the receipt of a report from the remote server, a set of rules restricting behaviors of the application is implemented at the local device. In some cases, in response to the receipt of a report from the remote server, the installation of the application on the local device is prevented.

Claims (32)

1. A system, comprising:

a processor configured to:

receive an indication that an attempt is being made to install an application on a local device;

in response to receiving the indication, transmit a request to a remote server for information associated with the application;

allow limited execution at the local device of a first executing copy of the application, pending receipt of a report from the remote server, wherein the received report comprises behaviors observed as being taken by a second copy of the application executed in a virtualized environment provided by the remote server, wherein the limited execution of the first executing copy of the application that is executing on the local device has a reduced set of functionality compared to functionality that can be provided by the same application when execution is not limited during another execution of the first executing copy on the local device; and

in response to the receipt of the report from the remote server, implement, at the local device, a set of rules restricting behaviors of the application installed on the local device; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the processor is further configured to detect an attempt by the first executing copy of the application to take an action that would violate the set of rules.

3. The system of claim 2 , wherein the set of rules comprises a whitelisted set of behaviors observed at the remote server during execution of the second copy of the application in the virtualized environment and wherein an attempt by the first executing copy of the application while executing on the local device to take an action not included in the whitelisted set of behaviors constitutes a rule violation.

4. The system of claim 2 , wherein the processor is further configured to report the attempt to a user of the local device.

5. The system of claim 2 , wherein the processor is further configured to report the attempt to the remote server.

6. The system of claim 5 , wherein, in response to receiving the report, the remote server performs an evaluation of the second copy of the application.

7. The system of claim 1 , wherein the set of rules restricts the first executing copy of the application to the behaviors observed during execution of the second copy of the application in the virtualized environment.

8. The system of claim 1 , wherein the remote server is configured to evaluate an updated version of the application in response to receiving an indication that the attempt is being made to install the updated version of the application.

9. The system of claim 1 , wherein the processor is further configured to monitor an application repository for updates made to the application.

10. The system of claim 9 , wherein the processor is configured to monitor the application repository at least in part using an application programming interface made available by the application repository.

11. The system of claim 9 , wherein the processor is configured to monitor the application repository at least in part using a crawler.

12. A method, comprising:

receiving an indication that an attempt is being made to install an application on a local device;

in response to receiving the indication, transmitting a request to a remote server for information associated with the application;

allowing limited execution at the local device of a first executing copy of the application, pending receipt of a report from the remote server, wherein the received report comprises behaviors observed as being taken by a second copy of the application executed in a virtualized environment provided by the remote server, wherein the limited execution of the first executing copy of the application that is executing on the local device has a reduced set of functionality compared to functionality that can be provided by the same application when execution is not limited during another execution of the first executing copy on the local device; and

in response to the receipt of the report from the remote server, implementing, at the local device, a set of rules restricting behaviors of the application installed on the local device.

13. The method of claim 12 , further comprising detecting an attempt by the first executing copy of the application to take an action that would violate the set of rules.

14. The method of claim 13 , wherein the set of rules comprises a whitelisted set of behaviors observed at the remote server during execution of the second copy of the application in the virtualized environment and wherein an attempt by the first executing copy of the application while executing on the local device to take an action not included in the whitelisted set of behaviors constitutes a rule violation.

15. The method of claim 13 , further comprising reporting the attempt to a user of the local device.

16. The method of claim 13 , further comprising reporting the attempt to the remote server.

17. The method of claim 16 , wherein, in response to receiving the report, the remote server performs an evaluation of the second copy of the application.

18. The method of claim 12 , wherein the set of rules restricts the first executing copy of the application to the behaviors observed during execution of the second copy of the application in the virtualized environment.

19. The method of claim 12 , wherein the remote server is configured to evaluate an updated version of the application in response to receiving an indication that the attempt is being made to install the updated version of the application.

20. The method of claim 12 , further comprising monitoring an application repository for updates made to the application.

21. The method of claim 20 , wherein monitoring the application repository includes using an application programming interface made available by the application repository.

22. The method of claim 20 , wherein monitoring the application repository includes using a crawler.

Continuity (2)
Continuation 14927429 · Oct 29, 2015
Related Publication 20210264030A1 · Aug 26, 2021
References Cited (46)
US 6591306B1 · Redlich · 2003 [cited by applicant]
US 8171545B1 · Cooley · 2012 [cited by applicant]
US 8340633B1 · Rege · 2012 [cited by applicant]
US 9152694B1 · Padidar · 2015 [cited by applicant]
US 9413774B1 · Liu · 2016 [cited by applicant]
US 9614863B2 · Kim · 2017 [cited by applicant]
US 20020087876A1 · Larose · 2002 [cited by examiner]
US 20040225877A1 · Huang · 2004 [cited by applicant]
US 20060150256A1 · Fanton · 2006 [cited by examiner]
US 20080120611A1 · Aaron · 2008 [cited by applicant]
US 20080127292A1 · Cooper · 2008 [cited by examiner]
US 20090077544A1 · Wu · 2009 [cited by applicant]
US 20090328180A1 · Coles · 2009 [cited by examiner]
US 20110225619A1 · Kesireddy · 2011 [cited by applicant]
US 20120272318A1 · Doukhvalov · 2012 [cited by applicant]
US 20120331441A1 · Adamson · 2012 [cited by applicant]
US 20130031600A1 · Luna · 2013 [cited by applicant]
US 20130097660A1 · Das · 2013 [cited by applicant]
US 20130111591A1 · Topan · 2013 [cited by applicant]
US 20130145463A1 · Ghosh · 2013 [cited by examiner]
US 20130283377A1 · Das · 2013 [cited by examiner]
US 20130347094A1 · Bettini · 2013 [cited by applicant]
US 20140304700A1 · Kim · 2014 [cited by applicant]
US 20150237068A1 · Sandke · 2015 [cited by examiner]
US 20150319136A1 · Huagang · 2015 [cited by applicant]
US 20150319182A1 · Natarajan · 2015 [cited by applicant]
US 20150339475A1 · Feroz · 2015 [cited by applicant]
US 20160012220A1 · Padidar · 2016 [cited by applicant]
US 20160042191A1 · Enck · 2016 [cited by examiner]
US 20160162685A1 · Feroz · 2016 [cited by applicant]
US 20160180087A1 · Edwards · 2016 [cited by applicant]
US 20160253159A1 · Smith · 2016 [cited by applicant]
US 20160285897A1 · Gantman · 2016 [cited by applicant]
US 20160285914A1 · Singh · 2016 [cited by applicant]
US 20160321452A1 · Richardson · 2016 [cited by applicant]
US 20160330239A1 · Han · 2016 [cited by applicant]
US 20170093918A1 · Banerjee · 2017 [cited by applicant]
US 20170099592A1 · Loeb · 2017 [cited by applicant]
US 20170103201A1 · Fox · 2017 [cited by applicant]
US 20170147320A1 · Persson · 2017 [cited by applicant]
US 20170346843A1 · Zhang · 2017 [cited by applicant]
Author Unknown, Fire Eye Introduces New Mobile Security Integration for Samsung KNOX-Enabled Devices, Mar. 2, 2015. [cited by applicant]
Author Unknown, Intent, Android Developers, Downloaded from http://developer.android.com/reference/android/ content/Intent.html on Oct. 12, 2015. [cited by applicant]
Eswari et al., “A practical business security framework to combat malware threat,” World Congress on Internet Security (WorldCIS-2012), Guelph, ON, pp. 77-80. 2012. [cited by applicant]
Mujumdar et al., “Analysis of Signature-Based and Behavior-Based Anti-Malware Approaches”, from International Journal of Advanced Research in Computer Engineering and Technology (IJARCET), vol. 2, Issue 6, Jun. 2013. [cited by applicant]
Yang et al., IntentFuzzer: Detecting Capability Leaks of Android Applications, Jun. 2014. [cited by applicant]