EP3049986B1

Injection of data flow control objects into application processes

Abstract

This record has no abstract on file.

EP3049986B1, drawing sheet 1
Sheet 1 of 3

Term

7 yearsleft in the term

Expires 23 September 2033.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

8 claims: 5 independent, 3 dependent

  1. 1
    A non-transitory computer readable storage medium including executable instructions that, when executed by a processor, cause the processor to:using at least one of a kernel module and management instrumentation of an operating system, assign a callback to a creation event of an application process (218);and in response to detecting the creation event of the application process (218), execute the callback (232) that is assigned to the creation event of the application process (218), the execution of the callback (232) causing data flow control object code (216) to be injected into the application process (218) prior to the application process making system calls to the operating system, the data flow control object code (216) to provide functionality modification of the application process (218) by enforcing policies relating to the leakage of sensitive data by the application process (218), wherein, the data flow control object code (216) is operable to enforce the policies by intercepting a system call by the application process (218) that requests a flow of data out of the application process against the policies, and by controlling the flow of data according to the policies.
  2. 2
    The non-transitory computer readable storage medium of any preceding claim further comprising executable instructions that, when executed by the processor, cause the processor to suspend the application process (218) during the injection.
  3. 3
    The non-transitory computer readable storage medium of any preceding claim wherein the data flow control object code (216) is operable to control the flow of data according to the policies to prevent data from being exported by the application process (218), or to monitor, encrypt, or redact the data in response to the data being exported by the application process (218).
  4. 4
    A computer-implemented method comprising:assigning (100) a callback (232), using at least one of a kernel module and management instrumentation of an operating system, to a creation event of an application process (218);in response to detecting the creation event of the application process (218), executing (104) the callback (232) that is assigned to the creation event, the execution of the callback (232) causing data flow control object code (216) to be injected into the application process (218) prior to the application process (218) making system calls to the operating system, the data flow control object code (216) to provide functionality modification to the application process (218) by enforcing policies relating to the leakage of sensitive data by the application process, wherein the data flow control object code (216) is operable to enforce the policies by intercepting a system call by the application process (218) that requests a flow of data out of the application process against the policies, and by controlling the flow of data according to the policies.
  5. 7
    A computing device comprising:hardware resources;an operating system (220) to manage the hardware resources and to provide service for an application process (218), the operating system (220) having a kernel module or management instrumentation (226);and a callback (232) to be assigned to a creation event of an application process (218) using the kernel module or the management instrumentation (226), the callback (232) to be executed in response to the detection of the creation event to cause data flow control object code (216) to be injected into the application process (218) prior to the application process (218) making system calls to the operating system, the data flow control object code to provide functionality modification to the application process (218) by enforcing policies relating to the leakage of sensitive data by the application process (218), wherein the data flow control object code (216) is operable to enforce the policies by intercepting a system call by the application process (218) that requests a flow of data out of the application process against the policies, and by controlling the flow of data according to the policies.