Network Proxy Memory Layout Subversion for Browser Exploit Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing endpoint-based exploit mitigation technologies are difficult to manage, configure, and deploy, especially in large organizations, and can be evaded by kernel-based vulnerabilities, affecting user experience and compatibility.

Innovation Solution

A network-based system that injects a JavaScript library into HTTP(S) responses to manipulate and subvert memory content, breaking the predictive layout of client computer memory without installing an endpoint client, using a proxy to monitor and rewrite HTTP(S) responses and hook functions to mitigate memory corruption attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If endpoint-based exploit mitigation software is installed on computers, then exploit protection capability is improved, but device complexity and ease of operation deteriorate due to difficult management, configuration, and deployment requirements

Engineering Contradiction:
Improveexploit protection capabilityVSAvoidsoftware management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network-based intermediary system that sits between users and exploited resources, handling exploit mitigation centrally through a service architecture rather than requiring endpoint software. This intermediary approach transfers management complexity from individual endpoints to a centralized service, resolving the contradiction between protection capability and operational simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical approach of installing and managing software packages on each endpoint with a network-based service delivery model. Instead of physically deploying software through traditional installation mechanisms, the system uses network communication to deliver protection, eliminating the complexity associated with software package management, installation, and updates.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If endpoint-based mitigation software is deployed in large organizations, then exploit protection is improved, but ease of operation worsens due to difficult deployment and maintenance requirements

Engineering Contradiction:
Improveexploit protectionVSAvoiddeployment ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the mitigation functionality from endpoint systems and consolidates it into a centralized network service. This extraction eliminates the need for system administrators to manually install, configure, and maintain software on numerous individual endpoints, dramatically simplifying deployment in large organizations while maintaining comprehensive protection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network-based service provides universal exploit protection across multiple platforms and devices through a single centralized system. This multi-functional approach allows one service to protect diverse endpoints without requiring platform-specific software versions, simplifying deployment and maintenance across large organizational networks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If exploit mitigation software is installed on computers, then exploit protection is improved, but user experience deteriorates due to affected browsing session operation

Engineering Contradiction:
Improveexploit protectionVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent uses a network intermediary that operates transparently in the background, protecting users from exploits without requiring any changes to their browsing behavior or session operations. The intermediary handles protection mechanisms independently, allowing users to experience no degradation in their interaction with web content while maintaining robust security.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If endpoint-based mitigation software is used, then exploit protection capability is improved, but adaptability worsens as kernel-based vulnerabilities can evade the software

Engineering Contradiction:
Improveexploit protection capabilityVSAvoidvulnerability coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent shifts the protection dimension from endpoint-based to network-based, operating at the network communication layer rather than the operating system kernel level. This dimensional change allows the system to protect against a broader range of vulnerabilities including kernel-based exploits, since the protection occurs before data reaches the vulnerable endpoint systems.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10050995B2Method and system for destroying browser-based memory corruption vulnerabilities
Publication Date: 2018.08.14 CHECK POINT SOFTWARE TECH LTD
  • US10050995B2 patent drawing
  • US10050995B2 patent drawing
  • US10050995B2 patent drawing

AI summary

Client-less methods and systems destroy/break the predictive layout of, for example, a client computer memory. The methods and systems operate by injecting a library that manipulates the client computer memory during exploitation attempts.