The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 21, 2022

Filed:

May. 18, 2020
Applicant:

Crowdstrike, Inc., Irvine, CA (US);

Inventors:

Paul Meyer, Hudson, WI (US);

Cameron Gutman, Redmond, WA (US);

John R. Kooker, Poway, CA (US);

Assignee:

Crowd Strike, Inc., Irvine, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G06F 21/55 (2013.01); G06F 21/56 (2013.01);
U.S. Cl.
CPC ...
H04L 63/0263 (2013.01); G06F 21/554 (2013.01); G06F 21/566 (2013.01); H04L 63/0227 (2013.01); H04L 63/0236 (2013.01); G06F 21/56 (2013.01); G06F 21/562 (2013.01); G06F 2221/2115 (2013.01); H04L 63/02 (2013.01); H04L 63/1441 (2013.01);
Abstract

A computing device can install and execute a kernel-level security agent that interacts with a remote security system as part of a detection loop aimed at defeating malware attacks. The kernel-level security agent can be installed with a firewall policy that can be remotely enabled by the remote security system in order to 'contain' the computing device. Accordingly, when the computing device is being used, and a malware attack is detected on the computing device, the remote security system can send an instruction to contain the computing device, which causes the implementation, by an operating system (e.g., a Mac™ operating system) of the computing device, of the firewall policy accessible to the kernel-level security agent. Upon implementation and enforcement of the firewall policy, outgoing data packets from, and incoming data packets to, the computing device that would have been allowed prior to the implementation of the firewall policy are denied.


Find Patent Forward Citations

Loading…