The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Nov. 02, 2021

Filed:

Sep. 29, 2017
Applicant:

Crowdstrike, Inc., Irvine, CA (US);

Inventors:

Cat S. Zimmermann, Lake Forest Park, WA (US);

Steven King, Bellevue, WA (US);

Assignee:

CrowdStrike, Inc., Irvine, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/56 (2013.01); G06F 21/55 (2013.01); H04L 29/06 (2006.01); G06F 8/656 (2018.01); G06F 21/57 (2013.01); G06F 8/65 (2018.01); G06F 9/54 (2006.01);
U.S. Cl.
CPC ...
G06F 21/566 (2013.01); G06F 8/65 (2013.01); G06F 8/656 (2018.02); G06F 9/545 (2013.01); G06F 21/55 (2013.01); G06F 21/57 (2013.01); H04L 63/14 (2013.01); G06F 2221/033 (2013.01);
Abstract

A security agent for a host computing device may be implemented with multiple levels of indirection from an operating system (OS) kernel of the computing device in order to facilitate software upgrades for the security agent. An unserviceable kernel-mode component of the security agent may directly interface with the OS kernel and hook into a function (e.g., a security callback function) of the OS kernel in a first level of indirection, while a serviceable kernel-mode component of the security agent, which is upgradable, may indirectly interface with the OS kernel via the unserviceable kernel-mode component in a second level of indirection. The serviceable kernel-mode component may be configured to process events, and/or data related thereto, received from the OS kernel via the unserviceable kernel-mode component in order to monitor activity on the computing device for malware attacks.


Find Patent Forward Citations

Loading…