Patent · US Active

Hardened event counters for anomaly detection

US9842209B2 · kind B2 · utility

2Cited by
6References
25Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMay 8, 2015
Grant dateDec 12, 2017
Priority date
Expiry dateAug 3, 2035

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2221/2135
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

A collection of techniques allow for the detection of covert malware that attempts to hide its existence on a system by leveraging both trusted hardware event counters and the particular memory addresses (as well as the sequences of such addresses) of the instructions that are generating the suspected malicious activity. By monitoring the address distribution's specific patterns over time, one can build a behavioral model (i.e., “fingerprint”) of a particular process—and later attempt to match suspected malicious processes to the stored behavioral models. Whenever the actual measured behavior of a suspected malicious process fails to match said stored behavioral models, the system or system administrator may attempt to perform rehabilitative actions on the computer system to locate and remove the malware hiding on the system.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.