Invention Grant
- Patent Title: Rootkit detection based on system dump sequence analysis
-
Application No.: US17656971Application Date: 2022-03-29
-
Publication No.: US12013942B2Publication Date: 2024-06-18
- Inventor: Vladimir Strogov , Sergey Ulasen , Serguei Beloussov , Stanislav Protasov
- Applicant: Acronis International GmbH
- Applicant Address: CH Schaffhausen
- Assignee: Acronis International GmbH
- Current Assignee: Acronis International GmbH
- Current Assignee Address: CH Schaffhausen
- Agency: ESPE Legal Consultancy FZ-LLC
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F21/00

Abstract:
The present disclosure relates to a system and method for rootkit detection based on a system dump sequence analysis. The system includes a security system in communication with one or more applications of a computing system. The security system includes a system event monitor to monitor events occurring at the applications, a system dump capture driver to capture differential system dumps corresponding to each event, and a rootkit detection engine to determine if a system state is infected. The rootkit detection engine is based on a machine learning model, where the machine learning model is trained on collection of clean system dumps and infectious system dumps. Based on analysis carried out by the machine learning model, the rootkit detection engine can classify the system state as suspicious, infectious, or clean state.
Public/Granted literature
- US20230315850A1 Rootkit detection based on system dump sequence analysis Public/Granted day:2023-10-05
Information query