Invention Grant
- Patent Title: Firmware retrieval and analysis
-
Application No.: US16855585Application Date: 2020-04-22
-
Publication No.: US11599641B2Publication Date: 2023-03-07
- Inventor: Timo Kreuzer , Ion-Alexandru Ionescu , Aaron LeMasters
- Applicant: CrowdStrike, Inc.
- Applicant Address: US CA Irvine
- Assignee: CrowdStrike, Inc.
- Current Assignee: CrowdStrike, Inc.
- Current Assignee Address: US CA Irvine
- Agency: Lee & Hayes, P.C.
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/57 ; G06F13/42 ; G06F21/44

Abstract:
A bus filter driver and security agent components configured to retrieve and analyze firmware images are described herein. The bus filter driver may attach to a bus device associated with a memory component and retrieve a firmware image of firmware stored on the memory component. The bus filter driver may also retrieve hardware metadata. A kernel-mode component of the security agent may then retrieve the firmware image and hardware metadata from the bus filter driver and provide the firmware image and hardware metadata to a user-mode component of the security agent for security analysis. The security agent components may then provide results of the analysis and/or the firmware image and hardware metadata to a remote security service to determine a security status for the firmware.
Public/Granted literature
- US20200342110A1 FIRMWARE RETRIEVAL AND ANALYSIS Public/Granted day:2020-10-29
Information query