US2023297676A1PendingUtilityA1

Systems and methods for code injection detection

Assignee: CAPITAL ONE SERVICES LLCPriority: Apr 13, 2020Filed: May 26, 2023Published: Sep 21, 2023
Est. expiryApr 13, 2040(~13.7 yrs left)· nominal 20-yr term from priority
Inventors:Jon Whitmore
G06F 21/552G06F 21/566G06F 21/554G06F 2221/033G06F 21/565
65
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A computer-implemented method for detecting a code injection threat may include: performing a search process on a memory of a computer system to identify property list files; in response to an identification of a property list file, retrieving the property list file; performing an analysis process on the property list file to identify a target identifier; in response to an identification of the target identifier in the property list file, determining whether the target identifier corresponds to an electronic application stored in the memory of the computer system; in response to determining that the target identifier corresponds to the electronic application, determining that the property list file is indicative of a code injection threat to the electronic application; and in response to the determination that the property list file is indicative of a code injection threat to the electronic application, performing a security action based on the property list.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A computer-implemented method for detecting a code injection threat, comprising:
 performing a search process on a memory of a computer system to identify property list files, wherein the search process is configured such that property list files have a visibility to the search process that is dependent on whether the computer system has been compromised;   in response to an identification of a property list file, determining that the property list file is indicative of a code injection threat to the computer system; and   in response to the determination that the property list file is indicative of a code injection threat to the computer system, performing a security action based on the property list.   
     
     
         22 . The computer-implemented method of  claim 21 , wherein performing the search process on the memory includes using a file manager protocol of the computer system. 
     
     
         23 . The computer-implemented method of  claim 21 , wherein the performing the search process on the memory includes using low-level input-output functions of the computer system. 
     
     
         24 . The computer-implemented method of  claim 23 , wherein the performing the search process on the memory further includes:
 using a file manager protocol of the computer system;   wherein the using of the low-level input-output functions is performed in response to not finding any property list files using the file manager protocol.   
     
     
         25 . The computer-implemented method of  claim 21 , wherein determining that the property list file is indicative of a code injection threat to the computer system includes:
 parsing the property list file to extract a bundle identifier; and   identifying whether the bundle identifier matches a target identifier of an electronic application stored in the memory of the computer system.   
     
     
         26 . The computer-implemented method of  claim 25 , further comprising:
 in response to determining the bundle identifier matches the target identifier, transmitting an alert message to a detection server system, the alert message indicating that the electronic application is a target of a code injection threat.   
     
     
         27 . The computer-implemented method of  claim 25 , wherein the performing the security action includes transmitting an alert message to a detection server system, the alert message indicating that the electronic application is a target of a code injection threat. 
     
     
         28 . The computer-implemented method of  claim 25 , wherein the performing the security action includes terminating the electronic application. 
     
     
         29 . The computer-implemented method of  claim 28 , wherein the performing the security action further includes preventing the electronic application from being executed until an indication that a security status of the computer system has been restored. 
     
     
         30 . The computer-implemented method of  claim 21 , wherein preforming the search process includes comparing results of (i) searching the memory using a file manager protocol of the computer system and (ii) searching the memory using low-level input-output functions of the computer system. 
     
     
         31 . A system for detecting a code injection threat, the system comprising:
 a memory storing instructions and an electronic application; and   a processor operatively connected to the memory and configured to execute the instructions to perform acts that include:   receiving a launch application instruction to execute the electronic application;   in response to receiving the launch application instruction, performing a security check process, the security check process including:
 performing a search process on the memory to identify property list files, wherein the search process is configured such that property list files have a visibility to the search process that is dependent on whether the system has been compromised; 
 in response to an identification of a property list file, determining that the property list file is indicative of a code injection threat to the system; and 
 in response to the determination that the property list file is indicative of a code injection threat to the system, performing a security action based on the property list that includes preventing the electronic application from being executed. 
   
     
     
         32 . The system of  claim 31 , wherein performing the search process on the memory includes using a file manager protocol of the system. 
     
     
         33 . The system of  claim 31 , wherein performing the search process on the memory includes using low-level input-output functions of the system. 
     
     
         34 . The system of  claim 33 , wherein performing the search process on the memory further includes:
 using a file manager protocol of the computer system;   wherein the using of the low-level input-output functions is performed in response to not finding any property list files using the file manager protocol.   
     
     
         35 . The system of  claim 31 , wherein determining that the property list file is indicative of a code injection threat to the computer system includes:
 parsing the property list file to extract a bundle identifier; and   identifying whether the bundle identifier matches a target identifier of an electronic application stored in the memory of the computer system.   
     
     
         36 . The system of  claim 35 , wherein the operations further include:
 in response to determining the bundle identifier matches the target identifier, transmitting an alert message to a detection server system, the alert message indicating that the electronic application is a target of a code injection threat.   
     
     
         37 . The system of  claim 36 , wherein performing the security action further includes transmitting an alert message to a detection server system, the alert message indicating that the electronic application is a target of a code injection threat. 
     
     
         38 . The system of  claim 36 , wherein the security check process further includes:
 in response to determining that the property list file is indicative of a code injection threat to the system, updating a threat variable associated with the electronic application to indicate that the electronic application was subject to a code injection threat.   
     
     
         39 . The system of  claim 31 , wherein the security check process further includes:
 in response to receiving another launch application instruction, performing the security check process again;   in response to the security check process determining no threat to the system, retrieving a threat variable;   determining whether the threat variable indicates that the system was previously subject to a code injection threat;   in response to determining the threat variable indicates that the electronic application was previously subject to a code injection threat, determining whether a security status of the system has been restored relative to when the system was previously subject to the code injection threat;   in response to determining that security status of the system has not been restored, determining the security check process has been circumvented; and   in response to determining the security check has been circumvented, transmitting a circumvented message to a server, the circumvented message indicating that the code injection threat was previously detected but is no longer detectable.   
     
     
         40 . A non-transitory computer-readable memory comprising instructions for detecting a code injection threat, the instructions executable by at least one processor of a computer system to perform operations, including:
 performing a search process on a memory of the computer system to identify property list files, wherein the search process is configured such that property list files have a visibility to the search process that is dependent on whether the computer system has been compromised;   in response to an identification of a property list file, determining that the property list file is indicative of a code injection threat to the computer system; and   in response to the determination that the property list file is indicative of a code injection threat to the computer system, performing a security action based on the property list.

Join the waitlist — get patent alerts

Track US2023297676A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.