Invention Grant
- Patent Title: Hardened event counters for anomaly detection
-
Application No.: US14707977Application Date: 2015-05-08
-
Publication No.: US09842209B2Publication Date: 2017-12-12
- Inventor: Eliezer Tamir , Andreas Kleen , Alex Nayshtut , Vadim Sukhomlinov , Igor Muttik , Eliel Louzoun
- Applicant: McAfee Inc.
- Applicant Address: US CA Santa Clara
- Assignee: McAfee, LLC
- Current Assignee: McAfee, LLC
- Current Assignee Address: US CA Santa Clara
- Agency: Blank Rome, LLP
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F21/55

Abstract:
A collection of techniques allow for the detection of covert malware that attempts to hide its existence on a system by leveraging both trusted hardware event counters and the particular memory addresses (as well as the sequences of such addresses) of the instructions that are generating the suspected malicious activity. By monitoring the address distribution's specific patterns over time, one can build a behavioral model (i.e., “fingerprint”) of a particular process—and later attempt to match suspected malicious processes to the stored behavioral models. Whenever the actual measured behavior of a suspected malicious process fails to match said stored behavioral models, the system or system administrator may attempt to perform rehabilitative actions on the computer system to locate and remove the malware hiding on the system.
Public/Granted literature
- US20160328561A1 HARDENED EVENT COUNTERS FOR ANOMALY DETECTION Public/Granted day:2016-11-10
Information query