Invention Grant
- Patent Title: Modifying evasive code using correlation analysis
-
Application No.: US14988121Application Date: 2016-01-05
-
Publication No.: US10027692B2Publication Date: 2018-07-17
- Inventor: Roee Hay , Sagi Kedmi , Omer Tripp
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Francis Lammes; Stephen J. Walder, Jr.; Jeffrey S. LaBaw
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/50

Abstract:
An example computer-implemented method includes receiving, via a processor, an application to be tested, a set of intrusive monitoring capabilities, and a set of external monitoring capabilities. The method includes executing, via the processor, the application in a clean environment to generate unmonitored application behavior. The method includes executing, via the processor, the application with intrusive monitoring based on two randomly generated seeds to generate trigger events and external monitoring to detect changes of application behavior in response to the intrusive monitoring. The method includes computing, via the processor, a correlation measure between the trigger events and the detected changes in the application behavior. The method includes modifying, via the processor, the application in response to detecting the application is evasive based on the correlation measure.
Public/Granted literature
- US20170195347A1 Modifying Evasive Code Using Correlation Analysis Public/Granted day:2017-07-06
Information query