Invention Grant
- Patent Title: Identifying malicious executing code of an enclave
-
Application No.: US15984817Application Date: 2018-05-21
-
Publication No.: US10997289B2Publication Date: 2021-05-04
- Inventor: Juscelino Candido De Lima Junior , Breno H. Leitao , Camilla Ogurtsova , Marcel de Toledo Pineda
- Applicant: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Applicant Address: US NY Armonk
- Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Current Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Current Assignee Address: US NY Armonk
- Agency: Heslin Rothenberg Farley & Mesiti PC
- Agent William Hartwell; Matthew M. Hulihan
- Main IPC: G06F21/55
- IPC: G06F21/55 ; G06F21/53 ; G06N5/02 ; G06F11/34 ; G06F16/28

Abstract:
Identifying malicious code execution of executing subject code of a software enclave of a processing system follows a process that includes monitoring performance characteristics of the processing system attributed to execution of the subject code of the software enclave. The monitoring produces performance data, which is stored to a relational database. The process applies a classification model to the stored performance data to obtain an output, and, based on the output of the classification model, identifies anomalous behavior in the execution of the subject code and determines a confidence level that the anomalous behavior exhibits malicious activity. Based on the confidence level exceeding a threshold, the process determines that the executing subject code is malicious and initiates halting of the execution of the subject code.
Public/Granted literature
- US20190354680A1 IDENTIFYING MALICIOUS EXECUTING CODE OF AN ENCLAVE Public/Granted day:2019-11-21
Information query