The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Mar. 07, 2023

Filed:

Apr. 22, 2020
Applicant:

Crowdstrike, Inc., Irvine, CA (US);

Inventors:

Timo Kreuzer, Schonberg, DE;

Ion-Alexandru Ionescu, Seattle, WA (US);

Aaron LeMasters, New York, NY (US);

Assignee:

CrowdStrike, Inc., Irvine, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G06F 21/57 (2013.01); G06F 13/42 (2006.01); G06F 21/44 (2013.01);
U.S. Cl.
CPC ...
G06F 21/572 (2013.01); G06F 13/4221 (2013.01); G06F 21/44 (2013.01); G06F 2213/0024 (2013.01); G06F 2213/0026 (2013.01); G06F 2221/033 (2013.01);
Abstract

A bus filter driver and security agent components configured to retrieve and analyze firmware images are described herein. The bus filter driver may attach to a bus device associated with a memory component and retrieve a firmware image of firmware stored on the memory component. The bus filter driver may also retrieve hardware metadata. A kernel-mode component of the security agent may then retrieve the firmware image and hardware metadata from the bus filter driver and provide the firmware image and hardware metadata to a user-mode component of the security agent for security analysis. The security agent components may then provide results of the analysis and/or the firmware image and hardware metadata to a remote security service to determine a security status for the firmware.


Find Patent Forward Citations

Loading…