IP Library › Granted Patent US 12,199,950
Granted Patent B2
US 12,199,950 · App. 17/816,381 · Granted Jan 14, 2025

Security for computer systems

Inventors: Daniel Lahiano (Petah Tikva, IL); Vladimir Perelman (Tel Aviv, IL); Orr Moran (Tel Aviv, IL)
Assignee: Microsoft Technology Licensing, LLC.
H04L63/0254G06F16/1734G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,199,950
App. No.
17/816,381
Granted
Jan 14, 2025
Kind
B2
Abstract

Filesystem driver software can receive a file access request indicating that an application process is requesting to access a target file in a filesystem, Network filter driver software can receive a connection establishment request indicating that the application process running on the processing apparatus is requesting to establish a connection over a network with a target endpoint. According to the present disclosure, one or both of: a) the filesystem driver software is configured to grant or deny the file access request in dependence on state information from the network filter driver software, and/or b) the network filter driver software is configured to grant or deny the connection establishment request in dependence on state information from the filesystem driver software.

Claims (57)

1. A computer system comprising:

a processing apparatus comprising a processor,

memory comprising a memory device, and

a network interface comprising a network interface device;

the memory storing operating system software arranged to execute on the processing apparatus, the operating system software comprising instructions operative upon execution by the processing apparatus to:

receive, by filesystem driver software of the operating system software, a file access request indicating that an application process running on the processing apparatus is requesting access to a target file in a filesystem of the memory of the computer system;

receive, by the network filter driver software of the operating system software, a connection establishment request indicating that the application process running on the processing apparatus is requesting to establish a connection over a network with a target endpoint via the network interface of the computer system;

via a communication channel for sharing state between the filesystem driver software and the network filter driver software, accessing, by the filesystem driver software, network filter driver software state information; and

by the filesystem driver software, grant or deny the file access request in dependence on the network filter driver software state information.

2. The computer system of claim 1 , wherein the network filter driver software state information comprises an indication of whether there is any active network connection with an untrusted endpoint and the instructions are further operative, upon execution by the processing apparatus, to, by the filesystem driver software, determine whether the target file is designated as sensitive, wherein the granting or denying of the file access request is based on the network filter driver software state information according to a rule that: if the target file is designated as sensitive then the file access request will be denied unless the network filter driver software state information indicates no active connections to any untrusted endpoint.

3. The computer system of claim 1 , wherein the instructions are further operative upon execution by the processing apparatus to:

via the communication channel for sharing state between the filesystem driver software and the network filter driver software, accessing, by the network filter driver software, filesystem driver software state information; and

by the network filter driver software, grant or deny the connection establishment request in dependence on the filesystem driver software state information.

4. The computer system of claim 3 , wherein the filesystem driver software state information comprises an indication of whether the application process has ever read from or written to a file designated as sensitive and the instructions are further operative, upon execution by the processing apparatus, to, by the network filter driver software, determine whether the target endpoint is trusted and the network filter driver software is operative to perform the granting or denying of the connection establishment request based on the filesystem driver software state information according to a rule that: if the target endpoint is untrusted, the connection establishment request will be granted only on condition that the filesystem driver software state information indicates that the application process has never read from or written to any sensitive file, but otherwise the file access request will be denied.

5. The computer system of claim 1 , wherein the network filter driver software state information includes an indication of whether there is any active network connections with an untrusted endpoint, the filesystem driver software denying the file access request upon the network filter driver software state information indicating that an active network connection with any untrusted endpoint exists.

6. The computer system of claim 1 , wherein:

the network filter driver software receives filesystem driver software state information from the filesystem driver software via the communication channel;

the filesystem driver software state information comprises an indication of whether the application process has ever read from or written to any sensitive file; and

the network filter driver software denies the connection establishment request unless the target endpoint is trusted or the filesystem driver software state information indicates that the application process has never read from or written to any sensitive file.

7. The computer system of claim 1 , wherein:

the operating system software comprises a filesystem driver manager operative upon execution by the processing apparatus to receive the file access request from the application process via a system call layer of the operating system software, and each of one or more filesystem drivers comprised by the filesystem driver software is operative upon execution by the processing apparatus to receive the file access request by subscribing to have file access requests for the target file forwarded from the filesystem driver manager; and

the operating system software comprises a network filter driver manager operative upon execution by the processing apparatus to receive the connection establishment request from the application process via the system call layer, and each of one or more network filter drivers comprised by the network filter driver software is operative upon execution by the processing apparatus to receive the connection establishment request by subscribing to have connection establishment requests for the target endpoint forwarded from the network filter driver manager.

8. The computer system of claim 7 , wherein:

the one or more filesystem drivers comprises a first filesystem driver and a second filesystem driver, the second filesystem driver being operative upon execution by the processing apparatus to perform the granting or denying of the file access request, and the first filesystem driver being operative upon execution by the processing apparatus to access the memory and thereby execute the file access request when granted;

the one or more network filter drivers comprise a first network filter driver and a second network filter driver, the second network filter driver being operative upon execution by the processing apparatus to perform the granting or denying of the connection establishment request, and the first network filter driver being operative upon execution by the processing apparatus to implement one or more other network filter rules for granting or denying the connection establishment request or blocking an existing connection based on information other than a state of the filesystem driver software; and

the communication channel is established between the second filesystem driver and the second network filter driver.

9. The computer system of claim 8 , wherein the first filesystem driver comprises a first minifilter, the second filesystem driver comprises a second minifilter, the filesystem driver manager comprises a minifilter manager, the first network filter driver comprises a first operating system filtering platform callout driver, the second network filter driver comprises a second operating system filtering platform callout driver, and the network filter driver manager comprises an operating system filtering platform engine.

10. The computer system of claim 1 , wherein the network filter driver software comprises a single integrated network filter driver operative upon execution by the processing apparatus to perform the granting or denying of the connection establishment request based on filesystem driver software state information received by the network filter driver software via the communication channel, and to implement one or more other network filter rules for granting or denying the connection establishment request or blocking an existing connection based on information other than a state of the filesystem driver software.

11. A method of operating a computer system comprising a processing apparatus that includes at least one processor, memory, and a network interface, the method comprising:

receiving, by filesystem driver software of an operating system software, a file access request indicating that an application process running on the processing apparatus is requesting to access a target file in a filesystem of the memory of the computer system;

receiving, by network filter driver software of the operating system software, a connection establishment request indicating that the application process running on the processing apparatus is requesting establishment of a connection over a network with a target endpoint via the network interface of the computer system;

via a communication channel for sharing state between the filesystem driver software and the network filter driver software, accessing, by the network filter driver software, filesystem driver software state information; and

by the network filter driver software, granting or denying the connection establishment request in dependence on the filesystem driver software state information.

12. The method of claim 11 , further comprising, by the network filter driver software, determining whether the target endpoint is trusted, wherein;

the filesystem driver software state information comprises an indication of whether the application process has ever read from or written to any file designated as sensitive; and

the granting or denying of the connection establishment request is based on the filesystem driver software state information according to a rule that: if the target endpoint is untrusted, the connection establishment request will be denied unless the filesystem driver software state information indicates that the application process has never read from or written to any sensitive file.

13. The method of claim 11 , further comprising:

via the communication channel for sharing state between the filesystem driver software and the network filter driver software, accessing, by the filesystem driver software, network filter driver software state information; and

by the filesystem driver software, determining whether to grant or deny the file access request in dependence on the network filter driver software state information.

14. The method of claim 13 , wherein the network filter driver software state information comprises an indication of whether any untrusted network connections are currently active via the network interface, the method further comprising determining, by the filesystem driver software, whether the target file is designated as sensitive, wherein the granting or denying of the file access request by the filesystem driver software is based on the network filter driver software state information according to a rule that: if the target file is designated as sensitive then the file access request will be denied unless the network filter driver software state information indicates no active connections to any untrusted endpoint exist.

15. The method of claim 11 , wherein the filesystem driver software state information includes an indication of whether the application process has ever read from or written to any file designated as sensitive, the network filter driver software denying the connection establishment request upon the filesystem driver software state information indicating that the application process has ever read from or written to any file designated as sensitive.

16. The method of claim 11 , wherein:

the filesystem driver software receives network filter driver software state information from the network filter driver software via the communication channel;

the network filter driver software state information comprises an indication of whether any untrusted network connections are currently active via the network interface; and

the filesystem driver software denies the file access request unless the target file is not designated as sensitive or the network filter driver software state information indicates no active connections to any untrusted endpoint exists.

17. An operating system software for a computer system embodied on non-transitory computer-readable storage, the operating system software comprising filesystem driver software and network filter driver software, the computer operating system software being operative upon execution to:

receive, by the filesystem driver software of the operating system software, a file access request indicating that an application process running on the computer system is requesting to access a target file in a filesystem of a memory of the computer system;

receive, by the filesystem driver software and via a communication channel for sharing state between the filesystem driver software and the network filter driver software, network filter driver software state information from the network filter driver software;

receive, by the network filter driver software of the operating system software, a connection establishment request indicating that the application process running on the computer system is requesting to establish a connection over a network with a target endpoint via a network interface of the computer system;

receive, by the network filter driver software and via the communication channel, filesystem driver software state information from the filesystem software driver;

by the filesystem driver software, grant or deny the file access request in dependence on the network filter driver software state information; and

by the network filter driver software, grant or deny the connection establishment request in dependence on the filesystem driver software state information.

18. The operating system software of claim 17 , wherein the filesystem driver software is operative upon execution to determine whether the target file is designated as sensitive, and the network filter driver software state information comprises an indication of whether any untrusted network connections are currently active via the network interface, the filesystem driver software being operative to grant or deny the file access request according to a rule that if the target file is designated as sensitive then the file access request will be granted on condition that the network filter driver software state information indicates that no active connections to an untrusted endpoint exist.

19. The operating system software of claim 17 , wherein the network filter driver software is operative upon execution to determine whether the target endpoint is trusted, and the filesystem driver software state information comprises an indication of whether the application process has ever read from or written to any sensitive file, the network filter driver software being operative to grant or deny the connection establishment request according to a rule that if the target endpoint is untrusted, the connection establishment request will be denied unless the filesystem driver software state information indicates that the application process has never read from or written to any file designated as sensitive.

20. The operating system software of claim 17 , wherein:

the filesystem driver software is operative upon execution to determine whether the target file is designated as sensitive, and the network filter driver software state information comprises an indication of whether any untrusted network connections are currently active via the network interface, the filesystem driver software being operative to grant or deny the file access request according to a rule that if the target file is designated as sensitive then the file access request will be granted on condition that the network filter driver software state information indicates that no active connections to an untrusted endpoint exist; and

the network filter driver software is operative upon execution to determine whether the target endpoint is trusted, and the filesystem driver software state information comprises an indication of whether the application process has ever read from or written to any sensitive file, the network filter driver software being operative to grant or deny the connection establishment request according to a rule that if the target endpoint is untrusted, the connection establishment request will be granted only on condition that the filesystem driver software state information indicates that the application process has never read from or written to any file designated as sensitive, but otherwise the file access request will be denied.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2022
From: LACHINO, DANIEL; PERELMAN, VLADIMIR; MORAN, OR
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 061603/0318 →
Continuity (1)
Related Publication 20240039892A1 · Feb 1, 2024
References Cited (54)
US 5564017A · Corn · 1996 [cited by applicant]
US 5937159A · Meyers · 1999 [cited by examiner]
US 7904447B1 · Russell · 2011 [cited by applicant]
US 8544073B2 · Walter Silhavy · 2013 [cited by applicant]
US 8695090B2 · Barile et al. · 2014 [cited by applicant]
US 9047476B2 · Chawla et al. · 2015 [cited by applicant]
US 9384359B2 · Jacobson et al. · 2016 [cited by applicant]
US 11082444B2 · Macleod et al. · 2021 [cited by applicant]
US 11134104B2 · Qureshi et al. · 2021 [cited by applicant]
US 20060288008A1 · Bhattiprolu · 2006 [cited by applicant]
US 20080263653A1 · Lee · 2008 [cited by applicant]
US 20120163180A1 · Goel et al. · 2012 [cited by applicant]
US 20140223513A1 · Islam · 2014 [cited by applicant]
US 20150095597A1 · Ayanam et al. · 2015 [cited by applicant]
US 20170091482A1 · Sarin et al. · 2017 [cited by applicant]
US 20170364707A1 · Lal · 2017 [cited by examiner]
US 20180336334A1 · Yadav et al. · 2018 [cited by applicant]
US 20190349357A1 · Shukla et al. · 2019 [cited by applicant]
US 20200074097A1 · Hamlin · 2020 [cited by examiner]
US 20210311641A1 · Prakashaiah et al. · 2021 [cited by applicant]
US 20210312077A1 · Jain et al. · 2021 [cited by applicant]
US 20210344602A1 · Lewin et al. · 2021 [cited by applicant]
US 20230336465A1 · Lewin et al. · 2023 [cited by applicant]
CN 111343132A · 2020 [cited by applicant]
JP 2009026022A · 2009 [cited by examiner]
KR 100976602B1 · 2010 [cited by applicant]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US20023/23040”, Mailed Date: Aug. 18, 2023, 14 Pages. [cited by applicant]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US2023/015150”, Mailed Date: Jun. 16, 2023, 15 Pages. [cited by applicant]
“Notice of Allowance Issued in U.S. Appl. No. 17/720,133”, Mailed Date: Jun. 5, 2023, 9 Pages. [cited by applicant]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US2023/023309”, Mailed Date: Sep. 15, 2023, 15 Pages. [cited by applicant]
“Get-SmbConnection”, Retrieved from: https://docs.microsoft.com/en-us/powershell/module/smbshare/get-smbconnection?view-windowsserver2022-ps, Retrieved On: Aug. 21, 2022 , 3 Pages. [cited by applicant]
Vice, et al., “Overview: VPN Split Tunneling for Microsoft 365”, Retrieved from: https://docs.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-vpn-split-tunnel?view=o365-worldwide, Mar. 4, 2022, 12 Pages. [cited by applicant]
“Border Gateway Protocol”, Retrieved from: https://en.wikipedia.org/wiki/Border_Gateway_Protocol, Mar. 24, 2022, 18 Pages. [cited by applicant]
“Check Point: Route-Based”, Retrieved from: https://web.archive.org/web/20220324200852/https://docs.oracle.com/en-us/iaas/Content/Network/Reference/checkpointCPEroutebased.htm, Mar. 24, 2022, 8 Pages. [cited by applicant]
“Introduction—Valtix Documentation”, Retrieved from: https://docs.valtix.com/aws/aws_workshop/introduction/, Retrieved from: Apr. 21, 2022, 2 Pages. [cited by applicant]
“Meraki SD-WAN”, Retrieved from: https://documentation.meraki.com/Architectures_and_Best_Practices/Cisco_Meraki_Best_Practice_Design/Best_Practice_Design_-_MX_Security_and_SD-WAN/Meraki_SD-WAN, Mar. 28, 2022, 34 Pages. [cited by applicant]
“MX Addressing and VLANs”, Retrieved from: https://documentation.meraki.com/MX/Networks_and_Routing/MX_Addressing_and_VLANs, Jun. 17, 2021, 4 Pages. [cited by applicant]
“Networks and Tunnel Routing”, Retrieved from: https://cloud.google.com/network-connectivity/docs/vpn/concepts/choosing-networks-routing, Retrieved on: Apr. 21, 2022, 9 Pages. [cited by applicant]
“Secure Application Workloads with Palo Alto Networks VM-Series Firewall”, Retrieved from: https://docs.oracle.com/en/solutions/secure-app-palo-alto-firewall/index.html#GUID-CB6D7F26-0DEA-4B27-A265-E6169D8992E9, Retriev… [cited by applicant]
“Site-to-Site VPN Overview”, Retrieved from: https://web.archive.org/web/20220120084208/https://docs.oracle.com/en-us/iaas/Content/Network/Tasks/overviewIPsec.htm, Jan. 20, 2022, 9 Pages. [cited by applicant]
“Traffic Management”, Retreieved from: https://web.archive.org/web/20220301215855/https://istio.io/latest/docs/concepts/traffic-management/, Mar. 1, 2022, 16 Pages. [cited by applicant]
“What is a Network Load Balancer?”, Retrieved from: https://web.archive.org/web/20201214113601/https://docs.aws.amazon.com/elasticloadbalancing/latest/network/introduction.html, Dec. 14, 2020, 3 Pages. [cited by applicant]
“What is an Application Load Balancer?”, Retrieved from: https://web.archive.org/web/20201213163849/https://docs.aws.amazon.com/elasticloadbalancing/latest/application/introduction.html, Dec. 13, 2020, 4 Pages. [cited by applicant]
Bender, et al., “Virtual Network Traffic Routing”, Retrieved from: https://docs.microsoft.com/en-us/azure/virtual-network/virtual-networks-udr-overview#custom-routes, Apr. 16, 2022, 19 Pages. [cited by applicant]
Keil, Matt, “Threat and Data-Theft Prevention Policies with VM-Series”, Retrieved from: https://cloud.google.com/architecture/partners/threat-and-data-theft-prevention-policies-with-vm-series#protecting_apps_from_inboun… [cited by applicant]
Majumder, et al., “Dynamic Routing”, Retrieved from: https://docs.citrix.com/en-us/citrix-sd-wan/current-release/routing/dynamic-routing.html, Jul. 28, 2021, 9 Pages. [cited by applicant]
Majumder, et al., “Zscaler Integration by using GRE Tunnels and IPsec Tunnels”, Retrieved from: https://docs.citrix.com/en-us/citrix-sd-wan/current-release/security/citrix-sd-wan-secure-web-gateway/sd-wan-web-secure-gat… [cited by applicant]
Panni, Jess, “AWS vs Azure vs Google Cloud Platform—Networking”, Retrieved from: https://endjin.com/blog/2016/11/aws-vs-azure-vs-google-cloud-platform-networking, Nov. 14, 2016, 18 Pages. [cited by applicant]
Patel, Ashish, “Azure—Difference between Azure ExpressRoute and Azure VPN Gateway”, Retrieved from: https://medium.com/awesome-azure/azure-difference-between-azure-expressroute-and-azure-vpn-gateway-comparison-azure-hyb… [cited by applicant]
Patel, Ashish, “Azure—Difference between Azure Load Balancer and Application Gateway”, Retrieved from: https:// medium.com/awesome-azure/azure-difference-between-azure-load-balancer-and-application-gateway-9a6019c23840,… [cited by applicant]
Vaidyanathan, et al., “Network Transformation with AWS and Valtix for Workload Segmentation and Compliance”, Retrieved from: https://aws.amazon.com/blogs/apn/network-transformation-with-aws-and-valtix-for-workload-segme… [cited by applicant]
Vice, et al., “Implementing VPN Split Tunneling for Microsoft 365”, Retrieved from: https://docs.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-vpn-implement-split-tunnel?view=o365-worldwide#common-vpn-scena… [cited by applicant]
Non-Final Office Action mailed on Apr. 25, 2024, in U.S. Appl. No. 17/847,117, 10 pages. [cited by applicant]
Final Office Action issued in U.S. Appl. No. 17/847,117, mailed on Sep. 10, 2024, 9 Pages. [cited by applicant]