Invention Grant
- Patent Title: Detecting anomalies in program execution
-
Application No.: US16274479Application Date: 2019-02-13
-
Publication No.: US10558509B2Publication Date: 2020-02-11
- Inventor: Rachel E. Craik , Allan Kielstra , Ying Chau Raymond Mak , Melanie Ullmer
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Endicott Drafting Center
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F11/07 ; G06F21/12 ; G06F21/50 ; G06F21/55

Abstract:
Techniques are described for detecting anomalous behavior in program execution. In one example, a method includes logging occurrence of one or more key run time events during execution of a program. Each key run time event has a corresponding key run time event data structure associated with the program, and logging includes storing records associated with the key run time events, wherein each record is based on the key run time event data structure associated with the key run time event. The method further includes analyzing the records to determine if a current pattern of key run time events associated with the program during execution matches an expected pattern of key run time events and generating a security alert if the current pattern of key run time events does not match the expected pattern of key run time events for the program.
Public/Granted literature
- US20190179686A1 DETECTING ANOMALIES IN PROGRAM EXECUTION Public/Granted day:2019-06-13
Information query