Systems and methods for protecting web conferences from intruders

US12101323B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12101323-B2
Application numberUS-202117527836-A
CountryUS
Kind codeB2
Filing dateNov 16, 2021
Priority dateDec 23, 2020
Publication dateSep 24, 2024
Grant dateSep 24, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Disclosed herein are systems and methods for providing network protection for web-based conferencing services. In one aspect, an exemplary system comprises, a device comprising a processor, an operating system (OS) operable in a user mode and a kernel mode, and a kernel driver for performing operations while the OS is in kernel mode, the kernel driver configured to: monitor file operations that involve objects belonging to a web conferencing service, receive a request from an application executing in a user mode, the request being for an operation to be executed in the kernel mode, when the operation involves at least one object belonging to the web conferencing service, request for an authorization from a protection service executing in the user mode, and allow the operation to be performed only when the authorization is received from the protection service.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method for providing network protection for web-based conferencing services, the method comprising: monitoring, by a kernel driver and a file system and registry filter, file operations to detect operations that involve objects belonging to a web conferencing service; receiving, by the kernel driver, a request from an application executing in a user mode, the request being for an operation to be executed in the kernel mode; when the operation involves at least one object belonging to the web conferencing service, requesting, by the kernel driver, for an authorization from a protection service executing in the user mode, wherein the at least one object is a registry item and the operation is modifying the registry item, wherein the protection service is configured to deny the request in response to detecting, using a plurality of rules, that modifying the registry item is associated with enabling access to a meeting without permission or direct invitation; and allowing, by the kernel driver, the operation to be performed only when the authorization is received from the protection service. 2. The method of claim 1 , wherein the monitoring is to detect file operations that perform at least one of: injecting processes, modifying registry keys in an operating system of the user endpoint device, and modifying at least one process of the web conferencing service. 3. The method of claim 1 , wherein the authorization is based on the application from which the request is received. 4. The method of claim 1 , further comprising: using a callback registration driver to register control callbacks which are called at process creation; and using the registered control callbacks for restricting access rights for creating processes and for actions during an open process. 5. The method of claim 1 , wherein an authorization for injecting of codes into running processes is based on verifications of signatures of running processes. 6. The method of claim 1 , wherein the protection service provides the authorization when the file operation is received from the application from an entity with a valid certificate. 7. The method of claim 1 , wherein the monitoring further comprises: monitoring to detect operations that access memory designated for confidential or personal information. 8. The method of claim 1 , wherein the protection service is further configured to deny the request in response to: detecting, using the plurality of rules, that modifying the registry item is associated with activating a camera and/or microphone of a computing device executing an application of the web conferencing service, or storing a recording in a storage location accessible without permission. 9. The method of claim 1 , wherein the object is a file comprising code that controls transmission of audio and video content captured via the web conferencing service, wherein the operation comprises modifying the file, and wherein the protection service is configured to block modification of the file if the modifying is requested by an unauthorized entity. 10. A system of a device for providing network protection for web-based conferencing services, comprising: a hardware processor; an operating system (OS) operable in a user mode and a kernel mode; and a kernel driver configured to: monitor file operations that involve objects belonging to a web conferencing service; receive a request from an application executing in a user mode, the request being for an operation to be executed in the kernel mode; when the operation involves at least one object belonging to the web conferencing service, request for an authorization from a protection service executing in the user mode, wherein the at least one object is a registry item and the operation is modifying the registry item, wherein the protection service is configured to deny the request in response to detecting, using a plurality of rules, that modifying the registry item is associated with enabling access to a meeting without permission or direct invitation; and allow the operation to be performed only when the authorization is received from the protection service. 11. The system of claim 10 , wherein the monitoring is to detect file operations that perform at least one of: injecting processes, modifying registry keys in an operating system of the user endpoint device, and modifying at least one process of the web conferencing service. 12. The system of claim 10 , the authorization is based on the application from which the request is received. 13. The system of claim 10 , wherein the kernel driver is further configured to: use a callback registration driver to register control callbacks which are called at process creation; and use the registered control callbacks for restricting access rights for creating processes and for actions during an open process. 14. The system of claim 10 , wherein an authorization for injecting of codes into running processes is based on verifications of signatures of running processes. 15. The system of claim 10 , wherein the protection service provides the authorization when the file operation is received from the application from an entity with a valid certificate. 16. The system of claim 10 , wherein the kernel driver is further configured to: monitor to detect operations that access memory designated for confidential or personal information. 17. The system of claim 10 , wherein the protection service is further configured to deny the request in response to: detecting, using the plurality of rules, that modifying the registry item is associated with activating a camera and/or microphone of a computing device executing an application of the web conferencing service, or storing a recording in a storage location accessible without permission. 18. The system of claim 10 , wherein the object is a file comprising code that controls transmission of audio and video content captured via the web conferencing service, wherein the operation comprises modifying the file, and wherein the protection service is configured to block modification of the file if the modifying is requested by an unauthorized entity. 19. A non-transitory computer readable medium storing thereon computer executable instructions for providing network protection for web-based conferencing services, including instructions for: monitoring, by a kernel driver and a file system and registry filter of a user endpoint device, file operations to detect operations that involve objects belonging to a web conferencing service; receiving, by the kernel driver, a request from an application executing in a user mode, the request being for an operation to be executed in the kernel mode; when the operation involves at least one object belonging to the web conferencing service, requesting, by the kernel driver, for an authorization from a protection service executing in the user mode, wherein the at least one object is a registry item and the operation is modifying the registry item, wherein the protection service is configured to deny the request in response to detecting, using a plurality of rules, that modifying the registry item is associated with enabling access to a meeting without permission or direct invitation; and allowing, by the kernel driver, the operation to be performed only when the authorization is received from the protection service.

Assignees

Inventors

Classifications

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • during internet communication, e.g. revealing personal data from cookies · CPC title

  • to a single file or object, e.g. in a secure envelope, encrypted and accessed using a key, or with access control rules appended to the object itself · CPC title

  • Entity profiles · CPC title

  • Arrangements for multi-party communication, e.g. for conferences (data switching systems for conference H04L12/18; arrangements for connecting several subscribers to a common circuit, i.e. affording conference facilities H04M3/56; television conferencing systems H04N7/15) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12101323B2 cover?
Disclosed herein are systems and methods for providing network protection for web-based conferencing services. In one aspect, an exemplary system comprises, a device comprising a processor, an operating system (OS) operable in a user mode and a kernel mode, and a kernel driver for performing operations while the OS is in kernel mode, the kernel driver configured to: monitor file operations that…
Who is the assignee on this patent?
Acronis Int Gmbh
What technology area does this patent fall under?
Primary CPC classification H04L63/101. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Sep 24 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).