The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Oct. 01, 2019

Filed:

Sep. 25, 2017
Applicant:

Bromium, Inc., Cupertino, CA (US);

Inventors:

Ian Pratt, Cambridge, GB;

Rahul C. Kashyap, Foster City, CA (US);

Adrian Taylor, Cambridge, GB;

James M. McKenzie, Cambridge, GB;

Assignee:

Bromium, Inc., Cupertino, CA (US);

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/00 (2013.01); G06F 21/57 (2013.01); G06F 21/55 (2013.01); H04L 29/06 (2006.01); G06F 9/455 (2018.01); G06F 21/56 (2013.01);
U.S. Cl.
CPC ...
G06F 21/577 (2013.01); G06F 9/45558 (2013.01); G06F 21/552 (2013.01); G06F 21/554 (2013.01); H04L 63/1416 (2013.01); G06F 21/56 (2013.01); G06F 2009/45587 (2013.01); H04L 63/1433 (2013.01);
Abstract

Approaches for monitoring a host operating system. A threat model is stored and maintained in an isolated execution environment. The threat model identifies for any process executing on a host operating system how trustworthy the process should be deemed based on a pattern of observed behavior. The execution of the process and those processes in a monitoring circle relationship thereto are monitored. The monitoring circle relationship includes a parent process, any process in communication with a member of monitoring circle relationship, and any process instantiated by a present member of monitoring circle relationship. Observed process behavior is correlated with the threat model. Upon determining that a particular process has behaved in a manner inconsistent with a pattern of allowable behavior identified by the threat model for that process, a responsive action is taken.


Find Patent Forward Citations

Loading…