Invention Grant
- Patent Title: Kernel-level security agent
- Patent Title (中): 内核级安全代理
-
Application No.: US13492672Application Date: 2012-06-08
-
Publication No.: US09043903B2Publication Date: 2015-05-26
- Inventor: David F. Diehl , Dmitri Alperovitch , Ion-Alexandru Ionescu , George Robert Kurtz
- Applicant: David F. Diehl , Dmitri Alperovitch , Ion-Alexandru Ionescu , George Robert Kurtz
- Applicant Address: US CA Irvine
- Assignee: CrowdStrike, Inc.
- Current Assignee: CrowdStrike, Inc.
- Current Assignee Address: US CA Irvine
- Agency: Lee & Hayes, PLLC
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/56 ; G06F9/46 ; G06F21/55

Abstract:
A kernel-level security agent is described herein. The kernel-level security agent is configured to observe events, filter the observed events using configurable filters, route the filtered events to one or more event consumers, and utilize the one or more event consumers to take action based at least on one of the filtered events. In some implementations, the kernel-level security agent detects a first action associated with malicious code, gathers data about the malicious code, and in response to detecting subsequent action(s) of the malicious code, performs a preventative action. The kernel-level security agent may also deceive an adversary associated with malicious code. Further, the kernel-level security agent may utilize a model representing chains of execution activities and may take action based on those chains of execution activities.
Public/Granted literature
- US20130333040A1 Kernel-Level Security Agent Public/Granted day:2013-12-12
Information query