Invention Grant
- Patent Title: System and method for zero-day privilege escalation malware detection
-
Application No.: US15093690Application Date: 2016-04-07
-
Publication No.: US09959406B2Publication Date: 2018-05-01
- Inventor: Hiran Viswanath , Babu Mahadappa Mehtre
- Applicant: INSTITUTE FOR DEVELOPMENT AND RESEARCH IN BANKING TECHNOLOGY
- Applicant Address: IN Hyderabad
- Assignee: INSTITUTE FOR DEVELOPMENT AND RESEARCH IN BANKING TECHNOLOGY
- Current Assignee: INSTITUTE FOR DEVELOPMENT AND RESEARCH IN BANKING TECHNOLOGY
- Current Assignee Address: IN Hyderabad
- Agency: Patent 360 LLC
- Agent Barry Choobin
- Priority: IN6477/CHE/2015 20151202
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/55 ; G06F21/56

Abstract:
The various embodiments herein disclose a system and method for detecting zero-day privilege escalation malware at host level. The method identifies whether a privileged escalation state is initiated and executed by a user or by a malware program. The method uses keystrokes, Mouse events along with OCR output extracted from recorded background screen image for checking if user has initiated the privilege escalation. If a new process starts automatically without any pattern in Key Strokes, Mouse Strokes and background screen, then the process is identified as zero-day privilege escalation malware.
Public/Granted literature
- US20170161495A1 SYSTEM AND METHOD FOR ZERO-DAY PRIVILEGE ESCALATION MALWARE DETECTION Public/Granted day:2017-06-08
Information query