Invention Grant
- Patent Title: Kernel- and user-level cooperative security processing
-
Application No.: US15857007Application Date: 2017-12-28
-
Publication No.: US10740459B2Publication Date: 2020-08-11
- Inventor: David F. Diehl , Milos Petrbok , Colin Christopher McCambridge , Aaron Putnam
- Applicant: CrowdStrike, Inc.
- Applicant Address: US CA Irvine
- Assignee: CrowdStrike, Inc.
- Current Assignee: CrowdStrike, Inc.
- Current Assignee Address: US CA Irvine
- Agency: Lee & Hayes, P.C.
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F21/55 ; G06F21/53 ; H04L9/32 ; G06F21/60 ; H04L29/06

Abstract:
Some examples detect malicious activity on a computing device. A processor in kernel mode detects an event on the computing device. The processor provides a validation request on a kernel-level bus. A bidirectional bridge component transmits the request to a user-level bus. The processor in user mode determines that the event is associated with malicious activity and provides a validation response on the user-level bus. The bridge component transmits the validation response to the kernel-level bus. In some examples, the processor in user mode receives security-relevant information from a system service of the computing device, and analyzes the event based at least in part on the security-relevant information. In some examples, the processor in user mode receives a security query, queries the kernel mode via the bridge component, and responds to the security query indicating that the data stream is associated with malware.
Public/Granted literature
- US20190205533A1 Kernel- and User-Level Cooperative Security Processing Public/Granted day:2019-07-04
Information query