Invention Grant
- Patent Title: Intrusion detection using dynamic tracing
- Patent Title (中): 使用动态跟踪的入侵检测
-
Application No.: US11269775Application Date: 2005-11-08
-
Publication No.: US08028336B2Publication Date: 2011-09-27
- Inventor: Christoph L. Schuba , Dwight Hare , Hal Stern
- Applicant: Christoph L. Schuba , Dwight Hare , Hal Stern
- Applicant Address: US CA Redwood City
- Assignee: Oracle America, Inc.
- Current Assignee: Oracle America, Inc.
- Current Assignee Address: US CA Redwood City
- Agency: Osha • Liang LLP
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F12/14 ; G06F12/16 ; G08B23/00

Abstract:
Techniques have been developed whereby dynamic kernel/user-level tracing may be employed to efficiently characterize runtime behavior of production code. Using dynamic tracing techniques, user space or kernel instruction sequences between system calls may be instrumented without access to source code. In some realizations, instrumentation may be interactively specified on a host system. In some realizations, instrumentation specifications may be supplied as functional definitions (e.g., as scripts and/or probe definitions) for installation on a host system. Using the developed techniques, data states, parameters passed and/or timing information may be sampled to provide more detailed insight into actual program behavior. In signature-oriented exploitations, more powerful intrusion signatures are possible. In anomaly-oriented exploitations, a more detailed “sense of self” may be developed to discriminate between normal and anomalous program behavior.
Public/Granted literature
- US20070107058A1 Intrusion detection using dynamic tracing Public/Granted day:2007-05-10
Information query