Invention Grant
- Patent Title: Detection of anomalous program execution using hardware-based micro-architectural data
-
Application No.: US14778007Application Date: 2013-11-05
-
Publication No.: US10025929B2Publication Date: 2018-07-17
- Inventor: Lakshminarasimhan Sethumadhavan , John Demme , Jared Schmitz , Adrian Tang , Sal Stolfo , Matthew Maycock
- Applicant: THE TRUSTEES OF COLUMBIA UNIVERSITY IN THE CITY OF NEW YORK , Lakshminarasimhan Sethumadhavan , John Demme , Jared Schmitz , Adrian Tang , Sal Stolfo , Matthew Maycock
- Applicant Address: US NY New York
- Assignee: The Trustees of Columbia University in the City of New York
- Current Assignee: The Trustees of Columbia University in the City of New York
- Current Assignee Address: US NY New York
- Agency: Occhiuti & Rohlicek LLP
- International Application: PCT/US2013/068451 WO 20131105
- International Announcement: WO2014/149080 WO 20140925
- Main IPC: H04L9/00
- IPC: H04L9/00 ; G06F21/56 ; G06F21/57 ; G06N99/00 ; H04L9/32 ; H04L29/06 ; G06F11/34

Abstract:
Disclosed are devices, systems, apparatus, methods, products, media and other implementations, including a method that includes obtaining hardware-based micro-architectural data, including hardware-based micro-architectural counter data, for a hardware device executing one or more processes, and determining based, at least in part, on the hardware-based micro-architectural data whether at least one of the one or more processes executing on the hardware device corresponds to a malicious process. In some embodiments, determining based on the hardware-based micro-architectural data whether the at least one of the one or more processes corresponds to a malicious process may include applying one or more machine-learning procedures to the hardware-based micro-architectural data to determine whether the at least one of the one or more processes corresponds to the malicious process.
Public/Granted literature
- US20160275288A1 DETECTION OF ANOMALOUS PROGRAM EXECUTION USING HARDWARE-BASED MICRO-ARCHITECTURAL DATA Public/Granted day:2016-09-22
Information query