×

Behavioral-based host intrusion prevention system

CAFC
  • US 8,776,218 B2
  • Filed: 07/21/2009
  • Issued: 07/08/2014
  • Est. Priority Date: 07/21/2009
  • Status: Active Grant
First Claim
Patent Images

1. A computer program product embodied in a non-transitory computer readable medium that, when executing on one or more computers, performs the steps of:

  • monitoring an executing computer process for an indication of malicious behavior, wherein the indication of the malicious behavior is a result of comparing an operation with a predetermined behavior, referred to as a gene, where the gene is stored for reference in a database and wherein the gene relates to at least one of API calls, registry access, process manipulation, and file system access;

    performing the monitoring step a number of times to collect a plurality of malicious behavior indications;

    comparing the plurality of malicious behavior indications to a predetermined collection of malicious behaviors, referred to as a phenotype, which comprises a grouping of specific genes that are typically present in a type of malicious code, and wherein the phenotype is one of a number of phenotypes that are ranked to create increasing levels of confidence that a runtime object is executing a behavior pattern comparable to a known family of malware;

    triggering a content analysis of the executing computer process when the plurality of malicious behavior indications for the executing computer process corresponds to one of the number of phenotypes having a predetermined level of confidence that the executing computer process contains a known family of malware, thereby providing a prediction that the executing computer process is the type of malicious code; and

    causing an action based on the prediction.

View all claims
  • 9 Assignments
Timeline View
Assignment View
    ×
    ×