IP Library › Granted Patent US 12,625,927
Granted Patent B2
US 12,625,927 · App. 16/784,037 · Granted May 12, 2026

System and method for analyzing a device

Inventors: Bahar Limaye (Leesburg, VA); Atif Ghauri (Bensalem, PA); Sean Wechter (Broomall, PA)
Assignee: Comcast Cable Communications, LLC
G06F21/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,625,927
App. No.
16/784,037
Granted
May 12, 2026
Kind
B2
Abstract

A system and method for analyzing a device are disclosed. In an aspect, a method can comprise determining a parameter of a device at a kernel level of a software stack associated with the device, analyzing the parameter to determine an event state, comparing the event state to a white list to determine a state of an alert trigger, and generating an alert in response to the determined state of the alert trigger.

Claims (85)

1 . An apparatus comprising:

one or more processors; and

memory storing processor executable instructions that, when executed by the one or more processors, cause the apparatus to:

monitor one or more of logical access to embedded software of a user device or physical access to hardware ports and sockets of the user device;

determine, based on the monitoring of the one or more of the logical access to embedded software of the user device or the physical access to hardware ports and sockets of the user device, a physical pattern of operation associated with the user device;

determine, based on one or more acceptable patterns of operation of the user device, that the physical pattern of operation associated with the user device is associated with a pattern of operation corresponding to a security issue; and

cause, based on the physical pattern of operation associated with the user device being associated with the pattern of operation corresponding to the security issue, the user device to be prevented from accessing hardware ports and sockets of the apparatus and an adjustment of a monitoring protocol of data traffic associated with the user device.

2 . The apparatus of claim 1 , wherein the processor executable instructions, when executed by the one or more processors, further cause the apparatus to send, based on the physical pattern of operation associated with the user device being associated with the pattern of operation corresponding to the security issue, a notification to the user device indicating that an account is suspended.

3 . The apparatus of claim 1 , wherein the physical pattern of operation corresponding to the security issue comprises one or more of an unauthorized interaction with a hardware interface associated with the user device, one or more unauthorized secure shell (SSH) commands, or one or more unauthorized Telnet commands.

4 . The apparatus of claim 1 , wherein the processor executable instructions that, when executed by the one or more processors, cause the apparatus to determine the physical pattern of operation associated with the user device, further cause the apparatus to determine a change to an operational process of the user device.

5 . The apparatus of claim 1 , wherein the processor executable instructions, when executed by the one or more processors, further cause the apparatus to change, based on the physical pattern of operation associated with the user device being associated with the pattern of operation corresponding to the security issue, one or more services associated with the user device.

6 . The apparatus of claim 1 , wherein the processor executable instructions, when executed by the one or more processors, further cause the apparatus to suspend, based on the physical pattern of operation associated with the user device being associated with the pattern of operation corresponding to the security issue, one or more services associated with the user device.

7 . The apparatus of claim 1 , wherein the pattern of operation corresponding to the security issue comprises a pattern of physical events.

8 . The apparatus of claim 1 , wherein the processor executable instructions that, when executed by the one or more processors, cause the apparatus to determine the physical pattern of operation associated with the user device further cause the apparatus to receive the physical pattern of operation from the user device.

9 . One or more non-transitory computer-readable media storing processor-executable instructions that, when executed by at least one processor, cause the at least one processor to:

monitor, by a computing device, one or more of logical access to embedded software of a user device or physical access to hardware ports and sockets of the user device;

determine, based on the monitoring of the one or more of the logical access to embedded software of the user device or the physical access to hardware ports and sockets of the user device, a physical pattern of operation associated with the user device;

determine, based on one or more acceptable patterns of operation of the user device, that the physical pattern of operation associated with the user device is associated with a pattern of operation corresponding to a security issue; and

cause, based on the physical pattern of operation associated with the user device being associated with the pattern of operation corresponding to the security issue, the user device to be prevented from accessing hardware ports and sockets of the computing device and an adjustment of a monitoring protocol of data traffic associated with the user device.

10 . The non-transitory computer-readable media of claim 9 , wherein the processor-executable instructions, when executed by the at least one processor, further cause the at least one processor to send, based on the physical pattern of operation associated with the user device being associated with the pattern of operation corresponding to the security issue, a notification to the user device indicating that an account is suspended.

11 . The non-transitory computer-readable media of claim 9 , wherein the physical pattern of operation corresponding to the security issue comprises one or more of an unauthorized interaction with a hardware interface associated with the user device, one or more unauthorized secure shell (SSH) commands, or one or more unauthorized Telnet commands.

12 . The non-transitory computer-readable media of claim 9 , wherein the processor-executable instructions that, when executed by the at least processor, cause the at least one processor to determine the physical pattern of operation associated with the user device, further cause the at least one processor to determine a change to an operational process of the user device.

13 . The non-transitory computer-readable media claim 9 , wherein the processor-executable instructions, when executed by the at least one processor, further cause the at least one processor to change, based on the physical pattern of operation associated with the user device being associated with the pattern of operation corresponding to the security issue, one or more services associated with the user device.

14 . The non-transitory computer-readable media claim 9 , wherein the-processor-executable instructions, when executed by the at least one processor, further cause the at least one processor to suspend, based on the physical pattern of operation associated with the user device being associated with the pattern of operation corresponding to the security issue, one or more services associated with the user device.

15 . The non-transitory computer-readable media of claim 9 , wherein the pattern of operation corresponding to the security issue comprises a pattern of physical events.

16 . The non-transitory computer-readable media of claim 9 , wherein the processor-executable instructions that, when executed by the at least one processor, cause the at least one processor to determine the physical pattern of operation associated with the user device, further cause the at least one processor to receive the physical pattern of operation from the user device.

17 . A system comprising:

a user device configured to:

send telemetry data; and

a computing device configured to:

monitor one or more of logical access to embedded software of the user device or physical access to hardware ports and sockets of the user device;

determine, based on the telemetry data and based on the monitoring of the one or more of the logical access to embedded software of the user device or the physical access to hardware ports and sockets of the user device, a physical pattern of operation,

determine, based on one or more acceptable patterns of operation of the user device, that the physical pattern of operation is associated with a pattern of operation corresponding to a security issue, and

cause, based on the physical pattern of operation being associated with the pattern of operation corresponding to the security issue, the user device to be prevented from accessing hardware ports and sockets of the computing device and an adjustment of a monitoring protocol of data traffic associated with the user device.

18 . The system of claim 17 , wherein the physical pattern of operation corresponding to the security issue comprises one or more of an unauthorized interaction with a hardware interface associated with the user device, one or more unauthorized secure shell (SSH) commands, or one or more unauthorized Telnet commands.

19 . The system of claim 17 , wherein the computing device is further configured to determine a change to an operational process of the user device.

20 . The system of claim 17 , wherein the computing device is further configured to change, based on the physical pattern of operation being associated with the pattern of operation corresponding to the security issue, one or more services associated with the user device.

21 . The system of claim 17 , wherein the computing device is further configured to suspend, based on the physical pattern of operation being associated with the pattern of operation corresponding to the security issue, one or more services associated with the user device.

22 . The system of claim 17 , wherein the pattern of operation corresponding to the security issue comprises a pattern of physical events.

23 . An apparatus comprising:

one or more processors; and

memory storing processor executable instructions that, when executed by the one or more processors, cause the apparatus to:

monitor one or more of logical access to embedded software of a user device or physical access to hardware ports and sockets of the user device;

determine, based on the monitoring of the one or more of the logical access to embedded software of the user device or the physical access to hardware ports and sockets of the user device, a parameter indicating a physical pattern of operation associated with the user device;

determine, based on the parameter, a security issue;

determine, based on the security issue, an alert;

determine, based on the alert, an alert priority; and

cause, based on the alert priority, the user device to be prevented from accessing hardware ports and sockets of the apparatus and an adjustment of a monitoring protocol of data traffic associated with the user device.

24 . The apparatus of claim 23 , wherein the processor executable instructions, when executed by the one or more processors, further cause the apparatus to determine, by a detection element embedded in a software stack associated with the user device, the parameter.

25 . The apparatus of claim 23 , wherein the processor executable instructions that, when executed by the one or more processors, cause the apparatus to determine the parameter, further cause the apparatus to determine a change to an internal process associated with the user device.

26 . The apparatus of claim 23 , wherein the processor executable instructions, when executed by the one or more processors, further cause the apparatus to send, based on the alert priority, a notification to the user device indicating that an account is suspended.

27 . The apparatus of claim 26 , wherein the processor executable instructions, when executed by the one or more processors, further cause the apparatus to change, based on the alert priority, one or more services associated with the user device.

28 . The apparatus of claim 26 , wherein the processor executable instructions, when executed by the one or more processors, further cause the apparatus to suspend, based on the alert priority, a service associated with the user device.

29 . The apparatus of claim 23 , wherein the processor executable instructions, when executed by the one or more processors, further cause the apparatus to determine, based on one or more of an unauthorized interaction with a hardware interface associated with the user device, one or more unauthorized secure shell (SSH) commands, or one or more unauthorized Telnet commands, a change to the parameter.

30 . One or more non-transitory computer-readable media storing processor-executable instructions that, when executed by at least one processor, cause the at least one processor to:

monitor, by computing device, one or more of logical access to embedded software of a user device or physical access to hardware ports and sockets of the user device;

determine, based on the monitoring of the one or more of the logical access to embedded software of the user device or the physical access to hardware ports and sockets of the user device, a parameter indicating a physical pattern of operation associated with the user device;

determine, based on the parameter, a security issue;

determine, based on the security issue, an alert;

determine, based on the alert, an alert priority; and

cause, based on the alert priority, the user device to be prevented from accessing hardware ports and sockets of the computing device and an adjustment of a monitoring protocol of data traffic associated with the user device.

31 . The non-transitory computer-readable media claim 30 , wherein the processor-executable instructions, when executed by the at least one processor, further cause the at least one processor to determine, by a detection element embedded in a software stack associated with the user device, the parameter.

32 . The non-transitory computer-readable media claim 30 , wherein processor-executable instructions that, when executed by the at least one processor, cause the at least one processor to determine the parameter, further cause the at least one processor to determine a change to an internal process associated with the user device.

33 . The non-transitory computer-readable media claim 30 , wherein the processor-executable instructions, when executed by the at least one processor, further cause the at least one processor to send, based on the alert priority, a notification to the user device indicating that an account is suspended.

34 . The non-transitory computer-readable media claim 33 , wherein the processor-executable instructions, when executed by the at least one processor, further cause the at least one processor to change, based on the alert priority, one or more services associated with the user device.

35 . The non-transitory computer-readable media claim 33 , wherein the-processor-executable instructions, when executed by the at least one processor, further cause the at least one processor to suspend a service associated with the user device.

36 . The non-transitory computer-readable media claim 30 , wherein the processor-executable instructions, when executed by the at least one processor, further cause the at least one processor to determine, based on one or more of an unauthorized interaction with a hardware interface associated with the user device, one or more unauthorized secure shell (SSH) commands, or one or more unauthorized Telnet commands, a change to the parameter.

37 . A system comprising:

a user device configured to:

send telemetry data; and

a computing device configured to:

monitor one or more of logical access to embedded software of the user device or physical access to hardware ports and sockets of the user device;

determine, based on the telemetry data and based on the monitoring of the one or more of the logical access to embedded software of the user device or the physical access to hardware ports and sockets of the user device, a parameter indicating a physical pattern of operation,

determine, based on the parameter, a security issue,

determine, based on the security issue, an alert,

determine, based on the alert, an alert priority, and

cause, based on the alert priority, the user device to be prevented from accessing hardware ports and sockets of the computing device and an adjustment of a monitoring protocol of data traffic associated with the user device.

38 . The system of claim 37 , wherein the computing device is further configured to determine, by a detection element embedded in a software stack associated with the user device, the parameter.

39 . The system of claim 37 , wherein the computing device is further configured to determine the parameter based on a change to an internal process associated with the user device indicated by the telemetry data.

40 . The system of claim 37 , wherein the computing device is further configured to send, based on the alert priority, a notification to the user device indicating that an account is suspended.

41 . The system of claim 40 , wherein the computing device is further configured to change, based on the alert priority, one or more services associated with the user device.

42 . The system of claim 40 , wherein the computing device is further configured to suspend a service associated with the user device.

43 . The system of claim 40 , wherein the user device is further configured to receive the notification indicating that the account is suspended.

44 . The system of claim 43 , wherein the computing device is configured to determine, based on the parameter, the security issue, the computing device is further configured to determine, based on a change in the parameter, the security issue.

45 . The system of claim 37 , wherein the computing device is further configured to determine, based on one or more of an unauthorized interaction with a hardware interface associated with the user device, one or more unauthorized secure shell (SSH) commands, or one or more unauthorized Telnet commands, a change to the parameter.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 19, 2023
From: LIMAYE, BAHAR; GHAURI, ATIF; WECHTER, SEAN
To: COMCAST CABLE COMMUNICATIONS, LLC
Reel/Frame 064315/0160 →
Continuity (3)
Continuation 15722950 · Oct 2, 2017
Continuation 13441397 · Apr 6, 2012
Related Publication 20200387582A1 · Dec 10, 2020
References Cited (43)
US 7671741B2 · Lax · 2010 [cited by examiner]
US 7797733B1 · Sallam · 2010 [cited by examiner]
US 8230505B1 · Ahrens et al. · 2012 [cited by applicant]
US 8281114B2 · Linetsky · 2012 [cited by examiner]
US 9817951B2 · Limaye et al. · 2017 [cited by applicant]
US 10592640B2 · Limaye et al. · 2020 [cited by applicant]
US 10826933B1 · Ismael · 2020 [cited by examiner]
US 11036836B2 · Touboul · 2021 [cited by examiner]
US 11301594B2 · Trim · 2022 [cited by examiner]
US 20020024950A1 · Fink · 2002 [cited by examiner]
US 20020129264A1 · Rowland · 2002 [cited by examiner]
US 20020178383A1 · Hrabik · 2002 [cited by examiner]
US 20040255162A1 · Kim · 2004 [cited by examiner]
US 20050246767A1 · Fazal · 2005 [cited by examiner]
US 20060095963A1 · Crosby · 2006 [cited by examiner]
US 20060150256A1 · Fanton et al. · 2006 [cited by applicant]
US 20070143851A1 · Nicodemus · 2007 [cited by examiner]
US 20070180509A1 · Swartz et al. · 2007 [cited by applicant]
US 20080039209A1 · Chen et al. · 2008 [cited by applicant]
US 20090125885A1 · Gayathri et al. · 2009 [cited by applicant]
US 20090177675A1 · Trumbull · 2009 [cited by examiner]
US 20090199296A1 · Xie · 2009 [cited by examiner]
US 20090222907A1 · Guichard · 2009 [cited by examiner]
US 20100046378A1 · Knapp · 2010 [cited by examiner]
US 20100064379A1 · Cassett et al. · 2010 [cited by applicant]
US 20100212012A1 · Touboul · 2010 [cited by examiner]
US 20120131675A1 · Dai · 2012 [cited by examiner]
US 20120254982A1 · Sallam · 2012 [cited by applicant]
US 20130014221A1 · Moore et al. · 2013 [cited by applicant]
US 20130081138A1 · Rados · 2013 [cited by examiner]
US 20130111547A1 · Kraemer · 2013 [cited by examiner]
US 20130269043A1 · Limaye et al. · 2013 [cited by applicant]
US 20130291106A1 · Simonoff · 2013 [cited by examiner]
US 20150047021A1 · Touboul · 2015 [cited by examiner]
US 20160357958A1 · Guidry · 2016 [cited by examiner]
US 20180137258A1 · Limaye et al. · 2018 [cited by applicant]
J. Clark, S. Leblanc and S. Knight, “Risks associated with USB Hardware Trojan devices used by insiders,” 2011 IEEE International Systems Conference, Montreal, QC, Canada, 2011, pp. 201-208. (Year: 2011). [cited by examiner]
S. Verma and A. Singh, “Data theft prevention & endpoint protection from unauthorized USB devices—Implementation,” 2012 Fourth International Conference on Advanced Computing (ICoAC), Chennai, India, 2012, pp. 1-4. (Year… [cited by examiner]
Apvrille, et al., “DigSig: Runtime Authentication of Binaries at Kernel Level.” In LISA, vol. 4, pp. 59-66. 2004. [cited by applicant]
Choi, et al., “Implementation of a TCG-based trusted computing in mobile device.” In Trust, Privacy and Security in Digital Business, pp. 18-27. Springer Berlin Heidelberg, 2008. [cited by applicant]
Jana, et al., “TxBox: Building Secure, Efficient Sandboxes with System Transactions,” Security and Privacy (SP), 2011 IEEE Symposium on , vol. no., pp. 329,344, May 22-25, 2011. [cited by applicant]
U.S. Appl. No. 13/441,397 (U.S. Pat. No. 9,817,951), filed Apr. 6, 2012 (Nov. 14, 2017), Bahar Limaye. [cited by applicant]
U.S. Appl. No. 15/722,950 (U.S. Pat. No. 10,592,640), filed Oct. 2, 2017 (Mar. 17, 2020), Bahar Limaye. [cited by applicant]