Device protection using pre-execution command interception and evaluation
Techniques are provided for device protection using pre-execution command interception and evaluation. One method comprises obtaining, by a software entity associated with an operating system kernel of a device, a command from a user prior to an execution of the command; providing, by the software entity associated with the operating system kernel, a request to an approval entity to evaluate whether to execute the command; and initiating the execution of the command based on a result of the evaluation, by the approval entity, of whether to execute the command. The approval entity may be identified by accessing a registry of one or more users that are authorized to provide an authorization to execute the command. The evaluation of whether to execute the command may comprise one or more tasks specified by a policy.
1 . A method, comprising:
obtaining, by at least one software entity of an operating system kernel of at least one processing device comprising a processor coupled to a memory, one or more commands from a user prior to an execution of the one or more commands on the at least one processing device, wherein the obtaining comprises the at least one software entity of the operating system kernel intercepting the one or more commands on the at least one processing device, prior to the execution of the one or more commands, wherein the operating system kernel holds the intercepted one or more commands during an evaluation of the intercepted one or more commands;
providing, by the at least one software entity of the operating system kernel, in response to the one or more commands, an approval request to at least one approval entity to evaluate whether to execute the one or more commands, wherein the approval request requests the at least one approval entity to approve the execution of the one or more commands on the at least one processing device; and
initiating the execution of the one or more commands based at least in part on a result of the evaluation, by the at least one approval entity, of whether to execute the intercepted one or more commands, wherein the operating system kernel releases the hold of the intercepted one or more commands for execution in response to the at least one approval entity approving the execution of the one or more commands on the at least one processing device;
wherein the method is performed by the at least one processing device.
2 . The method of claim 1 , wherein the at least one approval entity is identified by accessing a registry, associated with the at least one processing device, of one or more users that are authorized to provide an authorization to execute the one or more commands.
3 . The method of claim 1 , wherein the evaluation, by the at least one approval entity, of whether to execute the one or more commands comprises one or more tasks specified by a policy.
4 . The method of claim 1 , wherein the initiating the execution of the one or more commands further comprises providing the one or more commands to an operating system for execution.
5 . The method of claim 1 , further comprising performing a multi-factor authentication of one or more of the user and the at least one approval entity.
6 . The method of claim 1 , further comprising determining, by the at least one software entity associated with the operating system kernel, whether the one or more commands requires an authorization, prior to the execution of the one or more commands, by the at least one approval entity.
7 . The method of claim 6 , wherein the determining whether the one or more commands requires the authorization is based at least in part on a determination of whether the one or more commands comprises a command of at least one designated type.
8 . The method of claim 7 , wherein the determining whether the one or more commands comprises the command of the at least one designated type evaluates one or more of: one or more command properties and one or more command criteria.
9 . An apparatus comprising:
at least one processing device comprising a processor coupled to a memory;
the at least one processing device being configured to implement the following steps:
obtaining, by at least one software entity of an operating system kernel of at least one processing device comprising a processor coupled to a memory, one or more commands from a user prior to an execution of the one or more commands on the at least one processing device, wherein the obtaining comprises the at least one software entity of the operating system kernel intercepting the one or more commands on the at least one processing device, prior to the execution of the one or more commands, wherein the operating system kernel holds the intercepted one or more commands during an evaluation of the intercepted one or more commands;
providing, by the at least one software entity of the operating system kernel, in response to the one or more commands, an approval request to at least one approval entity to evaluate whether to execute the one or more commands, wherein the approval request requests the at least one approval entity to approve the execution of the one or more commands on the at least one processing device; and
initiating the execution of the one or more commands based at least in part on a result of the evaluation, by the at least one approval entity, of whether to execute the intercepted one or more commands, wherein the operating system kernel releases the hold of the intercepted one or more commands for execution in response to the at least one approval entity approving the execution of the one or more commands on the at least one processing device.
10 . The apparatus of claim 9 , wherein the at least one approval entity is identified by accessing a registry, associated with the at least one processing device, of one or more users that are authorized to provide an authorization to execute the one or more commands.
11 . The apparatus of claim 9 , wherein the evaluation, by the at least one approval entity, of whether to execute the one or more commands comprises one or more tasks specified by a policy.
12 . The apparatus of claim 9 , wherein the initiating the execution of the one or more commands further comprises providing the one or more commands to an operating system for execution.
13 . The apparatus of claim 9 , further comprising determining, by the at least one software entity associated with the operating system kernel, whether the one or more commands requires an authorization, prior to the execution of the one or more commands, by the at least one approval entity.
14 . The apparatus of claim 13 , wherein the determining whether the one or more commands requires the authorization is based at least in part on a determination of whether the one or more commands comprises a command of at least one designated type.
15 . The apparatus of claim 14 , wherein the determining whether the one or more commands comprises the command of the at least one designated type evaluates one or more of: one or more command properties and one or more command criteria.
16 . A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device to perform the following steps:
obtaining, by at least one software entity of an operating system kernel of at least one processing device comprising a processor coupled to a memory, one or more commands from a user prior to an execution of the one or more commands on the at least one processing device, wherein the obtaining comprises the at least one software entity of the operating system kernel intercepting the one or more commands on the at least one processing device, prior to the execution of the one or more commands, wherein the operating system kernel holds the intercepted one or more commands during an evaluation of the intercepted one or more commands;
providing, by the at least one software entity of the operating system kernel, in response to the one or more commands, an approval request to at least one approval entity to evaluate whether to execute the one or more commands, wherein the approval request requests the at least one approval entity to approve the execution of the one or more commands on the at least one processing device; and
initiating the execution of the one or more commands based at least in part on a result of the evaluation, by the at least one approval entity, of whether to execute the intercepted one or more commands, wherein the operating system kernel releases the hold of the intercepted one or more commands for execution in response to the at least one approval entity approving the execution of the one or more commands on the at least one processing device.
17 . The non-transitory processor-readable storage medium of claim 16 , wherein the at least one approval entity is identified by accessing a registry, associated with the at least one processing device, of one or more users that are authorized to provide an authorization to execute the one or more commands.
18 . The non-transitory processor-readable storage medium of claim 16 , wherein the evaluation, by the at least one approval entity, of whether to execute the one or more commands comprises one or more tasks specified by a policy.
19 . The non-transitory processor-readable storage medium of claim 16 , wherein the initiating the execution of the one or more commands further comprises providing the one or more commands to an operating system for execution.
20 . The non-transitory processor-readable storage medium of claim 16 , further comprising determining, by the at least one software entity associated with the operating system kernel, whether the one or more commands requires an authorization, prior to the execution of the one or more commands, by the at least one approval entity.