Invention Grant
- Patent Title: System and method for reverse command shell detection
-
Application No.: US16059499Application Date: 2018-08-09
-
Publication No.: US10599841B2Publication Date: 2020-03-24
- Inventor: Jeffrey Albin Kraemer
- Applicant: Carbon Black, Inc.
- Applicant Address: US MA Waltham
- Assignee: Carbon Black, Inc.
- Current Assignee: Carbon Black, Inc.
- Current Assignee Address: US MA Waltham
- Main IPC: G06F21/55
- IPC: G06F21/55 ; G06F21/56 ; G06F21/52 ; H04L29/06 ; G06F9/451

Abstract:
A system and method for detecting reverse command shell intrusions at a process-level on a user device is disclosed. In one embodiment, the system detects each process starting on an operating system of the user device, such as a mobile phone or laptop computer, and monitors Application Programming Interface (API) calls between each process and the operating system. The system then determines whether each process is associated with a reverse command shell intrusion based on information associated with each process and/or the API calls, and executes security policies against the processes associated with the reverse command shell intrusion to remediate the processes. In another embodiment, the system determines whether processes starting on a user device are associated with a reverse command shell intrusion by monitoring and analyzing information associated with the parent process of each process and/or API calls between each parent process and the operating system.
Public/Granted literature
- US20180373867A1 System and Method for Reverse Command Shell Detection Public/Granted day:2018-12-27
Information query