IP Library › Granted Patent US 12,231,445
Granted Patent B2
US 12,231,445 · App. 18/489,727 · Granted Feb 18, 2025

Security monitoring at operating system kernel level

Inventors: James Fahrny (Parker, CO); Kyong Park (Woodbine, MD)
Assignee: Comcast Cable Communications, LLC
H04L63/1416G06F21/53G06F21/54G06F21/552G06F21/554G06F21/57G06F21/64H04L9/3239H04L63/0823H04L63/101H04W12/06G06F2221/2141H04L63/126
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,231,445
App. No.
18/489,727
Granted
Feb 18, 2025
Kind
B2
Abstract

Methods and apparatus for real-time security monitoring on a computing device are presented. A system may define privileges to access hardware interfaces for each process of a plurality of processes executing on a computing device. The privileges may be defined in a privileged operating system level that controls root access to an operating system. In response to a determination that a process is attempting to access a hardware interface, the system may determine whether the process is privileged to access the hardware interface by checking the privileges. In response to determining that the process is not privileged to access the hardware interface, the intrusion detection agent may terminate the process.

Claims (139)

1. A method comprising:

storing, by a computing device, encrypted data indicative of a plurality of privileges associated with a process accessing a plurality of resources of the computing device;

based on the process attempting to access a first resource of the plurality of resources of the computing device, determining, using the encrypted data, that the process is privileged to access the first resource; and

allowing, based on the determining that the process is privileged, the process to access the first resource.

2. The method of claim 1 , wherein the process and a plurality of additional processes are executing on the computing device, and wherein the storing comprises storing, for the plurality of additional processes, additional encrypted data indicative of privileges associated with the additional processes accessing at least a portion of the plurality of resources of the computing device.

3. The method of claim 1 , wherein:

the process is associated with a root level kernel of an operating system of the computing device, and

the determining and the allowing are performed by a super root level kernel, of the operating system, that is inaccessible to the root level kernel.

4. The method of claim 1 , wherein the plurality of resources of the computing device comprise two or more of: a central processor, a video processor, a security processor, a memory or memory region, a file system, an audio/video output, a USB port, an Ethernet port, an antenna, a cable input, a wireless receiver, a serial port, an external memory unit, a high definition media interface, a ZigBee interface, an optical interface, an SATA interface, a key ladder, a memory-to-memory decryptor, a timer, a memory controller, a device driver, a kernel level operating system call, or a BIOS setting.

5. The method of claim 1 , further comprising:

detecting, for a hardware interface, a source of an incoming data packet; and

determining, using the encrypted data, whether the source is privileged to access the hardware interface.

6. The method of claim 1 , further comprising:

based on a second process attempting to access a second resource of the plurality of resources of the computing device, determining, using stored additional encrypted data indicative of privileges associated with the second process, that the second process is not privileged to access the second resource; and

preventing, based on the determining that the second process is not privileged, the second process from accessing the second resource.

7. The method of claim 1 , further comprising:

determining, based on a validation check performed after expiration of a validity period associated with the process, that the process is valid.

8. The method of claim 1 , further comprising:

determining, for the process, a validity period based on one or more of: a behavior of the process, one or more privileges for the process, or a risk of malicious attack via the process.

9. The method of claim 1 , further comprising:

detecting a triggering event comprising one or more of: an attempt to modify a privilege, an external instruction to modify or read a memory location, or an attempt to add code to a memory location; and

based on the detected triggering event, causing one or more of: reporting of a security breach to a remote server, displaying of a message indicating detected malicious activity, terminating a code fragment, terminating all application processes executing on the computing device, or rebooting of the computing device.

10. The method of claim 1 , wherein the determining and the allowing are performed by a super root level kernel of an operating system of the computing device, the method further comprising one or more of:

determining, by the super root level kernel and for each process attempting to access a resource of the plurality of resources of the computing device, whether the attempting process is privileged to access the resource; or

preventing modification of privileges by processes other than the super root level kernel.

11. A method comprising:

determining, by a computing device and for each of a plurality of process types, a validity period specific to the process type;

based on a first process attempting to access a first resource of a plurality of resources of the computing device, determining that a validity period, for a process type associated with the first process, has expired;

based on the determining that the validity period has expired, performing a validation check of the first process; and

based on the validation check indicating that the first process is valid, and based on the first process being privileged to access the first resource, allowing the first process to access the first resource.

12. The method of claim 11 , further comprising determining, for each process of a plurality of processes that comprises the first process, one or more privileges associated with the process accessing one or more resources of the plurality of resources.

13. The method of claim 11 , further comprising:

storing, for each process of a plurality of processes that comprises the first process, encrypted data indicative of one or more privileges associated with the process accessing one or more resources of the plurality of resources; and

determining, based on the encrypted data stored for the first process, that the first process is privileged to access the first resource.

14. The method of claim 11 , wherein the plurality of resources of the computing device comprise at least two of: a central processor, a video processor, a security processor, a memory or memory region, a file system, an audio/video output, a USB port, an Ethernet port, an antenna, a cable input, a wireless receiver, a serial port, an external memory unit, a high definition media interface, a ZigBee interface, an optical interface, an SATA interface, a key ladder, a memory-to-memory decryptor, a timer, a memory controller, a device driver, a kernel level operating system call, or a BIOS setting.

15. The method of claim 11 , further comprising performing, based on execution of the first process, a validation check of code separate from the first process.

16. The method of claim 11 , wherein the plurality of process types comprise one or more of:

processes that have previously attempted unprivileged access of one or more resources of the plurality of resources;

processes attempting to access one or more of a display device, a memory, or a communication port;

processes attempting to access BIOS settings of the computing device; or

processes attempting to access one or more predetermined resources of the plurality of resources.

17. The method of claim 11 , wherein the first process is associated with a root level kernel of an operating system of the computing device, the method further comprising:

determining, by a super root level kernel of the operating system, whether the first process is privileged to access the first resource, wherein the super root level kernel is inaccessible to the root level kernel.

18. A computing device comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, configure the computing device to:

store encrypted data indicative of a plurality of privileges associated with a process accessing a plurality of resources of the computing device;

based on the process attempting to access a first resource of the plurality of resources of the computing device, determine, using the encrypted data, that the process is privileged to access the first resource; and

allow, based on the determining that the process is privileged, the process to access the first resource.

19. The computing device of claim 18 , wherein the process and a plurality of additional processes are executing on the computing device, and wherein the instructions, when executed by the one or more processors, configure the computing device to store the encrypted data by storing, for the plurality of additional processes, additional encrypted data indicative of privileges associated with the additional processes accessing at least a portion of the plurality of resources of the computing device.

20. The computing device of claim 18 , wherein the process is associated with a root level kernel of an operating system of the computing device, and wherein the instructions, when executed by the one or more processors, configure the computing device to:

determine that the process is privileged by determining, by a super root level kernel of the operating system, that the process is privileged, wherein the super root level kernel is inaccessible to the root level kernel; and

allow the process to access the first resource by allowing, by the super root level kernel, the process to access the first resource.

21. The computing device of claim 18 , wherein the plurality of resources of the computing device comprise two or more of: a central processor, a video processor, a security processor, a memory or memory region, a file system, an audio/video output, a USB port, an Ethernet port, an antenna, a cable input, a wireless receiver, a serial port, an external memory unit, a high definition media interface, a ZigBee interface, an optical interface, an SATA interface, a key ladder, a memory-to-memory decryptor, a timer, a memory controller, a device driver, a kernel level operating system call, or a BIOS setting.

22. The computing device of claim 18 , wherein the instructions, when executed by the one or more processors, configure the computing device to:

detect, for a hardware interface, a source of an incoming data packet; and

determine, using the encrypted data, whether the source is privileged to access the hardware interface.

23. The computing device of claim 18 , wherein the instructions, when executed by the one or more processors, configure the computing device to:

based on a second process attempting to access a second resource of the plurality of resources of the computing device, determine, using stored additional encrypted data indicative of privileges associated with the second process, that the second process is not privileged to access the second resource; and

prevent, based on the determining that the second process is not privileged, the second process from accessing the second resource.

24. The computing device of claim 18 , wherein the instructions, when executed by the one or more processors, configure the computing device to:

determine, based on a validation check performed after expiration of a validity period associated with the process, that the process is valid.

25. The computing device of claim 18 , wherein the instructions, when executed by the one or more processors, configure the computing device to:

determine, for the process, a validity period based on one or more of: a behavior of the process, one or more privileges for the process, or a risk of malicious attack via the process.

26. The computing device of claim 18 , wherein the instructions, when executed by the one or more processors, configure the computing device to:

detect a triggering event comprising one or more of: an attempt to modify a privilege, an external instruction to modify or read a memory location, or an attempt to add code to a memory location; and

based on the detected triggering event, cause one or more of: reporting of a security breach to a remote server, displaying of a message indicating detected malicious activity, terminating a code fragment, terminating all application processes executing on the computing device, or rebooting of the computing device.

27. The computing device of claim 18 , wherein the instructions, when executed by the one or more processors, configure the computing device to:

determine that the process is privileged by determining, using a super root level kernel of an operating system of the computing device, that the process is privileged;

allow the process to access the first resource by allowing, by the super root level kernel, the process to access the first resource; and

one or more of:

determine, by the super root level kernel and for each process attempting to access a resource of the plurality of resources of the computing device, whether the attempting process is privileged to access the resource; or

prevent modification of privileges by processes other than the super root level kernel.

28. A computing device comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, configure the computing device to:

determine, for each of a plurality of process types, a validity period specific to the process type;

based on a first process attempting to access a first resource of a plurality of resources of the computing device, determine that a validity period, for a process type associated with the first process, has expired;

based on the determining that the validity period has expired, perform a validation check of the first process; and

based on the validation check indicating that the first process is valid, and based on the first process being privileged to access the first resource, allow the first process to access the first resource.

29. The computing device of claim 28 , wherein the instructions, when executed by the one or more processors, configure the computing device to determine, for each process of a plurality of processes that comprises the first process, one or more privileges associated with the process accessing one or more resources of the plurality of resources.

30. The computing device of claim 28 , wherein the instructions, when executed by the one or more processors, configure the computing device to:

store, for each process of a plurality of processes that comprises the first process, encrypted data indicative of one or more privileges associated with the process accessing one or more resources of the plurality of resources; and

determine, based on the encrypted data stored for the first process, that the first process is privileged to access the first resource.

31. The computing device of claim 28 , wherein the plurality of resources of the computing device comprise at least two of: a central processor, a video processor, a security processor, a memory or memory region, a file system, an audio/video output, a USB port, an Ethernet port, an antenna, a cable input, a wireless receiver, a serial port, an external memory unit, a high definition media interface, a ZigBee interface, an optical interface, an SATA interface, a key ladder, a memory-to-memory decryptor, a timer, a memory controller, a device driver, a kernel level operating system call, or a BIOS setting.

32. The computing device of claim 28 , wherein the instructions, when executed by the one or more processors, configure the computing device to perform, based on execution of the first process, a validation check of code separate from the first process.

33. The computing device of claim 28 , wherein the plurality of process types comprise one or more of:

processes that have previously attempted unprivileged access of one or more resources of the plurality of resources;

processes attempting to access one or more of a display device, a memory, or a communication port;

processes attempting to access BIOS settings of the computing device; or

processes attempting to access one or more predetermined resources of the plurality of resources.

34. The computing device of claim 28 , wherein the first process is associated with a root level kernel of an operating system of the computing device, and wherein the instructions, when executed by the one or more processors, configure the computing device to:

determine, by a super root level kernel of the operating system, whether the first process is privileged to access the first resource, wherein the super root level kernel is inaccessible to the root level kernel.

35. A non-transitory computer-readable medium storing instructions that, when executed, configure a computing device to:

store encrypted data indicative of a plurality of privileges associated with a process accessing a plurality of resources of the computing device;

based on the process attempting to access a first resource of the plurality of resources of the computing device, determine, using the encrypted data, that the process is privileged to access the first resource; and

allow, based on the determining that the process is privileged, the process to access the first resource.

36. The non-transitory computer-readable medium of claim 35 , wherein the process and a plurality of additional processes are executing on the computing device, and wherein the instructions, when executed, configure the computing device to store the encrypted data by storing, for the plurality of additional processes, additional encrypted data indicative of privileges associated with the additional processes accessing at least a portion of the plurality of resources of the computing device.

37. The non-transitory computer-readable medium of claim 35 , wherein the process is associated with a root level kernel of an operating system of the computing device, and wherein the instructions, when executed, configure the computing device to:

determine that the process is privileged by determining, by a super root level kernel of the operating system, that the process is privileged, wherein the super root level kernel is inaccessible to the root level kernel; and

allow the process to access the first resource by allowing, by the super root level kernel, the process to access the first resource.

38. The non-transitory computer-readable medium of claim 35 , wherein the plurality of resources of the computing device comprise two or more of: a central processor, a video processor, a security processor, a memory or memory region, a file system, an audio/video output, a USB port, an Ethernet port, an antenna, a cable input, a wireless receiver, a serial port, an external memory unit, a high definition media interface, a ZigBee interface, an optical interface, an SATA interface, a key ladder, a memory-to-memory decryptor, a timer, a memory controller, a device driver, a kernel level operating system call, or a BIOS setting.

39. The non-transitory computer-readable medium of claim 35 , wherein the instructions, when executed, configure the computing device to:

detect, for a hardware interface, a source of an incoming data packet; and

determine, using the encrypted data, whether the source is privileged to access the hardware interface.

40. The non-transitory computer-readable medium of claim 35 , wherein the instructions, when executed, configure the computing device to:

based on a second process attempting to access a second resource of the plurality of resources of the computing device, determine, using stored additional encrypted data indicative of privileges associated with the second process, that the second process is not privileged to access the second resource; and

prevent, based on the determining that the second process is not privileged, the second process from accessing the second resource.

41. The non-transitory computer-readable medium of claim 35 , wherein the instructions, when executed, configure the computing device to:

determine, based on a validation check performed after expiration of a validity period associated with the process, that the process is valid.

42. The non-transitory computer-readable medium of claim 35 , wherein the instructions, when executed, configure the computing device to:

determine, for the process, a validity period based on one or more of: a behavior of the process, one or more privileges for the process, or a risk of malicious attack via the process.

43. The non-transitory computer-readable medium of claim 35 , wherein the instructions, when executed, configure the computing device to:

detect a triggering event comprising one or more of: an attempt to modify a privilege, an external instruction to modify or read a memory location, or an attempt to add code to a memory location; and

based on the detected triggering event, cause one or more of: reporting of a security breach to a remote server, displaying of a message indicating detected malicious activity, terminating a code fragment, terminating all application processes executing on the computing device, or rebooting of the computing device.

44. The non-transitory computer-readable medium of claim 35 , wherein the instructions, when executed, configure the computing device to:

determine that the process is privileged by determining, using a super root level kernel of an operating system of the computing device, that the process is privileged;

allow the process to access the first resource by allowing, by the super root level kernel, the process to access the first resource; and

one or more of:

determine, by the super root level kernel and for each process attempting to access a resource of the plurality of resources of the computing device, whether the attempting process is privileged to access the resource; or

prevent modification of privileges by processes other than the super root level kernel.

45. A non-transitory computer-readable medium storing instructions that, when executed, configure a computing device to:

determine, for each of a plurality of process types, a validity period specific to the process type;

based on a first process attempting to access a first resource of a plurality of resources of the computing device, determine that a validity period, for a process type associated with the first process, has expired;

based on the determining that the validity period has expired, perform a validation check of the first process; and

based on the validation check indicating that the first process is valid, and based on the first process being privileged to access the first resource, allow the first process to access the first resource.

46. The non-transitory computer-readable medium of claim 45 , wherein the instructions, when executed, configure the computing device to determine, for each process of a plurality of processes that comprises the first process, one or more privileges associated with the process accessing one or more resources of the plurality of resources.

47. The non-transitory computer-readable medium of claim 45 , wherein the instructions, when executed, configure the computing device to:

store, for each process of a plurality of processes that comprises the first process, encrypted data indicative of one or more privileges associated with the process accessing one or more resources of the plurality of resources; and

determine, based on the encrypted data stored for the first process, that the first process is privileged to access the first resource.

48. The non-transitory computer-readable medium of claim 45 , wherein the plurality of resources of the computing device comprise at least two of: a central processor, a video processor, a security processor, a memory or memory region, a file system, an audio/video output, a USB port, an Ethernet port, an antenna, a cable input, a wireless receiver, a serial port, an external memory unit, a high definition media interface, a ZigBee interface, an optical interface, an SATA interface, a key ladder, a memory-to-memory decryptor, a timer, a memory controller, a device driver, a kernel level operating system call, or a BIOS setting.

49. The non-transitory computer-readable medium of claim 45 , wherein the instructions, when executed, configure the computing device to perform, based on execution of the first process, a validation check of code separate from the first process.

50. The non-transitory computer-readable medium of claim 45 , wherein the plurality of process types comprise one or more of:

processes that have previously attempted unprivileged access of one or more resources of the plurality of resources;

processes attempting to access one or more of a display device, a memory, or a communication port;

processes attempting to access BIOS settings of the computing device; or

processes attempting to access one or more predetermined resources of the plurality of resources.

51. The non-transitory computer-readable medium of claim 45 , wherein the first process is associated with a root level kernel of an operating system of the computing device, and wherein the instructions, when executed, configure the computing device to:

determine, by a super root level kernel of the operating system, whether the first process is privileged to access the first resource, wherein the super root level kernel is inaccessible to the root level kernel.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2024
From: FAHRNY, JAMES; PARK, KYONG
To: COMCAST CABLE COMMUNICATIONS, LLC
Reel/Frame 068470/0077 →
Continuity (3)
Continuation 16991592 · Aug 12, 2020
Continuation 15047138 · Feb 18, 2016
Related Publication 20240048573A1 · Feb 8, 2024
References Cited (20)
US 7113995B1 · Beukema et al. · 2006 [cited by applicant]
US 7120763B1 · Schafer · 2006 [cited by applicant]
US 10417399B2 · Wajs · 2019 [cited by examiner]
US 20030051169A1 · Sprigg · 2003 [cited by examiner]
US 20030172296A1 · Gunter · 2003 [cited by examiner]
US 20040003277A1 · Rabeler · 2004 [cited by applicant]
US 20050198489A1 · Wallace et al. · 2005 [cited by applicant]
US 20070079090A1 · Rajagopal et al. · 2007 [cited by applicant]
US 20080295174A1 · Fahmy et al. · 2008 [cited by applicant]
US 20140205099A1 · Christodorescu et al. · 2014 [cited by applicant]
US 20160124865A1 · Junghans et al. · 2016 [cited by applicant]
US 20170230336A1 · Bingham · 2017 [cited by examiner]
US 20180336361A1 · Gilani · 2018 [cited by examiner]
US 20210397709A1 · Ndu · 2021 [cited by examiner]
JP 2012083922A · 2012 [cited by applicant]
WO 2007132392A2 · 2007 [cited by applicant]
Dec. 4, 2001—OpenCable Application Platform Specification—Cable Television Laboratories. [cited by applicant]
May 2000—The DVB-Multimedia Home Platform, API for Interactive Digital TV Applications—Philips Forschungslaboratorien. [cited by applicant]
Jun. 23, 2017—European Search Report—EP 17156758.9. [cited by applicant]
Jun. 1, 2018—European Office Action—EP 17156758.9. [cited by applicant]