Application Protection via DLL Legitimacy Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional methods fail to detect and defend against indirect attacks that use system processes as a trampoline for malicious activities, such as dll injection and code modification, which exploit legal system processes to bypass security measures.

Innovation Solution

A method that intercepts process opening requests, analyzes the start address of dlls or modified codes, and uses cloud verdict services or antivirus engines to verify their legitimacy, employing API hooks and disassembly to differentiate between legal and malicious access attempts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional callback interception methods are used to verify process context, then legal system processes can access protected applications, but malicious attacks using system processes as trampolines cannot be detected

Engineering Contradiction:
Improveaccess capability for legal system processesVSAvoiddetection accuracy against indirect attacks
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by analyzing and verifying the legitimacy of code modules (DLLs, executables) before they are allowed to access protected applications. The system pre-establishes a verification mechanism that checks the origin and authenticity of code modules attempting to open protected processes, rather than relying solely on process context verification. This prevents malicious code from exploiting legal system processes as trampolines, while still allowing legitimate access.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If process context verification is performed on intercepted calls, then basic application features can function, but indirect attacks through injected DLLs remain undetected

Engineering Contradiction:
Improveoperation of basic application featuresVSAvoiddetection of injected DLLs and modified codes
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces an intermediary verification mechanism that acts as a mediator between the code module and the protected application. Instead of directly verifying process context, the system introduces a code module verification step that checks the legitimacy of the intermediary (DLL, executable) attempting to access the protected process. This intermediary verification layer detects injected DLLs and modified codes while allowing legitimate code modules to pass through, thus maintaining ease of operation for basic features while improving detection capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If read/write access is opened to protected applications, then system processes can perform privilege management and skin painting, but malware can read private data and modify codes

Engineering Contradiction:
Improveaccess functionality for system componentsVSAvoiddata theft and code modification by malware
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by implementing different access control policies for different code modules. Instead of uniformly allowing or blocking all access to protected applications, the system verifies each code module's legitimacy individually. Legitimate system processes (svchost.exe, privilege management components, skin painting components) are allowed to access protected applications, while malicious code modules are blocked. This selective verification approach maintains the necessary adaptability for system components while preventing harmful factors from affecting the protected application.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10990678B2Method to protect application running in a hostile environment
Publication Date: 2021.04.27 COMODO SECURITY SOLUTIONS INC
  • US10990678B2 patent drawing
  • US10990678B2 patent drawing
  • US10990678B2 patent drawing

AI summary

There is provided a method to protect applications running in a hostile environment, including against trampoline based attacks which use dll injection and code modification. The method includes protecting an application when access is performed from injected dll, and protecting the application when access is performed from modified codes.