- 专利标题: Detecting anomalies in program execution
-
申请号: US16274479申请日: 2019-02-13
-
公开(公告)号: US10558509B2公开(公告)日: 2020-02-11
- 发明人: Rachel E. Craik , Allan Kielstra , Ying Chau Raymond Mak , Melanie Ullmer
- 申请人: International Business Machines Corporation
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 代理机构: Endicott Drafting Center
- 主分类号: G06F21/00
- IPC分类号: G06F21/00 ; G06F11/07 ; G06F21/12 ; G06F21/50 ; G06F21/55
摘要:
Techniques are described for detecting anomalous behavior in program execution. In one example, a method includes logging occurrence of one or more key run time events during execution of a program. Each key run time event has a corresponding key run time event data structure associated with the program, and logging includes storing records associated with the key run time events, wherein each record is based on the key run time event data structure associated with the key run time event. The method further includes analyzing the records to determine if a current pattern of key run time events associated with the program during execution matches an expected pattern of key run time events and generating a security alert if the current pattern of key run time events does not match the expected pattern of key run time events for the program.
公开/授权文献
- US20190179686A1 DETECTING ANOMALIES IN PROGRAM EXECUTION 公开/授权日:2019-06-13
信息查询