×

System and method for intercepting process creation events

  • US 9,195,823 B1
  • Filed: 01/13/2014
  • Issued: 11/24/2015
  • Est. Priority Date: 11/30/2006
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method of detecting creation of processes, the method comprising:

  • injecting an interceptor module into a native operating system process;

    replacing, with the interceptor module, an address of a selected routine in an address table with an address to an interceptor routine of the interceptor module such that the native operating system process is configured to call the interceptor routine in place of the selected routine during a creation of a second process;

    obtaining at least one parameter from the native operating system process using the interceptor routine, wherein the at least one parameter corresponds to at least one characteristic of the second process;

    analyzing the at least one parameter to determine whether the second process corresponds to a program of interest;

    controlling the second process in response to determining that the second process corresponds to the program of interest;

    saving the at least one parameter;

    causing the second process to terminate;

    creating a third process having the at least one parameter;

    wherein the step of obtaining at least one parameter further comprises obtaining a name of the second process; and

    wherein the second process is a browser process and wherein the controlling the second process comprises reducing functionality of the browser process.

View all claims
  • 23 Assignments
Timeline View
Assignment View
    ×
    ×