IP Library Granted Patent US 12,380,215
Granted Patent B2
US 12,380,215 · App. 18/358,564 · Granted Aug 5, 2025

Cyber security boot status markers

Inventors: Garrett Moore (Ottawa, CA); Blair C. Foster, Jr. (Ottawa, CA)
Assignee: CrowdStrike, Inc.
G06F21/575G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,380,215
App. No.
18/358,564
Granted
Aug 5, 2025
Kind
B2
Abstract

Boot status markers record historical boot processes performed by a computer system. Each time the computer system boots, an operating system performs a boot process and interfaces with an antimalware driver. The antimalware driver determines the boot status markers that were set during previous boot processes. The antimalware driver may then classify other drivers based on the boot status markers set during the previous boot processes. The antimalware driver may then report driver classifications to the operating system. The operating system may then block, or allow, the drivers based on the driver classifications.

Claims (31)

1. A method that classifies a boot-start driver, comprising:

determining, by an antimalware driver during a current boot process associated with an operating system, a boot status marker set during a previous boot process;

determining, by the antimalware driver during the current boot process, a driver classification associated with the boot-start driver, the driver classification based on the boot status marker set during the previous boot process; and

reporting, by the antimalware driver during the current boot process, the driver classification to the operating system.

2. The method of claim 1 , wherein in response to the boot status marker, further comprising blocking an execution of the boot-start driver.

3. The method of claim 1 , wherein in response to the boot status marker, further comprising allowing an execution of the boot-start driver.

4. The method of claim 1 , wherein the determining of the boot status marker further comprises reading a memory storing the boot status marker set during the previous boot process.

5. The method of claim 1 , further comprising classifying the boot-start driver as boot critical in response to the boot status marker.

6. The method of claim 1 , further comprising determining the previous boot process successfully completed based on the boot status marker.

7. The method of claim 1 , further comprising reporting the boot status marker via a network interface to a service provider.

8. A computer system that evaluates a boot-start driver, comprising:

a central processing unit; and

a memory device storing instructions that, when executed by the central processing unit, perform operations, the operations comprising:

executing an antimalware driver during an Early Launch AntiMalware (ELAM) feature associated with a current boot process by an operating system;

determining, during the ELAM feature associated with the current boot process, a boot status marker set during a previous boot process; and

blocking or allowing an initialization of the boot-start driver during the current boot process based on the boot status marker set during the previous boot process.

9. The computer system of claim 8 , wherein the operations further comprise determining the boot status marker set by the antimalware driver during the previous boot process.

10. The computer system of claim 8 , wherein the operations further comprise assigning a driver classification associated with the boot-start driver based on the boot status marker set during the previous boot process.

11. The computer system of claim 8 , wherein the operations further comprise reading the boot status marker.

12. The computer system of claim 8 , wherein the operations further comprise classifying the boot-start driver as boot critical in response to the boot status marker.

13. The computer system of claim 8 , wherein the operations further comprise classifying the boot-start driver as non-boot critical in response to the boot status marker.

14. The computer system of claim 8 , wherein the operations further comprise classifying the boot-start driver as an unknown driver in response to the boot status marker.

15. The computer system of claim 8 , wherein the operations further comprise determining the boot-start driver is blockable in response to the boot status marker.

16. The computer system of claim 8 , wherein the operations further comprise writing the boot status marker to the memory device.

17. The computer system of claim 8 , wherein the operations further comprise determining the previous boot process successfully completed based on the boot status marker.

18. The computer system of claim 8 , wherein the operations further comprise reporting the boot status marker via a network interface to a cloud service provider.

19. A memory device storing instructions that, when executed by a central processing unit, perform operations that evaluate a boot-start driver, the operations comprising:

executing an antimalware driver during an Early Launch AntiMalware (ELAM) feature associated with a current boot process by an operating system;

reading, during the ELAM feature associated with the current boot process, a Unified Extensible Firmware Interface (UEFI) registry storing a boot status marker set by the antimalware driver during a previous boot process by the operating system; and

blocking or allowing an initialization of the boot-start driver during the current boot process based on the boot status marker read from the UEFI registry.

20. The memory device of claim 19 , wherein the operations further comprise determining a driver classification associated with the boot-start driver based on the boot status marker read from the UEFI registry.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2023
From: MOORE, GARRETT; FOSTER, BLAIR C., JR.
To: CROWDSTRIKE, INC.
Reel/Frame 064511/0912 →
Continuity (2)
Provisional Application 63504975 · May 30, 2023
Related Publication 20240403435A1 · Dec 5, 2024
References Cited (28)
US 8365297B1 · Parshin et al. · 2013 [cited by applicant]
US 8417962B2 · Novak et al. · 2013 [cited by applicant]
US 8793477B2 · Horvath et al. · 2014 [cited by applicant]
US 8869282B1 · Lazarowitz · 2014 [cited by applicant]
US 9021244B2 · Bobzin · 2015 [cited by applicant]
US 9129114B2 · Hamid · 2015 [cited by applicant]
US 9195832B1 · Rusakov · 2015 [cited by examiner]
US 9432397B2 · Hamid et al. · 2016 [cited by applicant]
US 10855674B1 · Geusz · 2020 [cited by examiner]
US 10963569B2 · Harris et al. · 2021 [cited by applicant]
US 11182486B2 · Cosgrove et al. · 2021 [cited by applicant]
US 20150347757A1 · Yakovlev · 2015 [cited by examiner]
US 20160306978A1 · Thadikaran · 2016 [cited by examiner]
US 20180285570A1 · Leblanc · 2018 [cited by examiner]
US 20190384917A1 · Shah · 2019 [cited by examiner]
US 20200089888A1 · Kelly · 2020 [cited by examiner]
US 20200389491A1 · Buck · 2020 [cited by examiner]
US 20200394300A1 · Harris · 2020 [cited by examiner]
US 20200394305A1 · Cosgrove · 2020 [cited by examiner]
US 20210044623A1 · Bosch · 2021 [cited by examiner]
US 20210312057A1 · Kloth · 2021 [cited by examiner]
US 20230273799A1 · DeJong · 2023 [cited by examiner]
US 20230325510A1 · Tu · 2023 [cited by examiner]
CN 107451463 · 2017 [cited by applicant]
RU 2538287 · 2014 [cited by applicant]
Branco, Rodrigo Rubira; Shamir, Udi. Architecture for automation of malware analysis. 2010 5th International Conference on Malicious and Unwanted Software. https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=566578… [cited by examiner]
Malenko, Maja; Baunach Marcel. Device Driver and System Call Isolation in Embedded Devices. 2019 22nd Euromicro Conference on Digital System Design (DSD). https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=8875063… [cited by examiner]
Adelstein, Frank et al. Malicious code detection for open firmware. 18th Annual Computer Security Applications Conference, 2002. Proceedings. https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=1176312 (Year: 2002). [cited by examiner]