Malware and anomaly detection via activity recognition based on sensor data
First Claim
1. A system for providing malware and anomaly detection via activity recognition based on sensor data, the system comprising:
- a memory that stores instructions;
a processor that executes the instructions to perform operations, the operations comprising;
analyzing sensor data collected during a selected time period from at least one sensor associated with a device;
determining a context of the device when the device is in a connected state, wherein the context of the device is determined based on the sensor data collected during the selected time period, wherein the context of the device comprises an indication as to a physical orientation of the device and a position of the device;
determining if traffic received or transmitted by the device during the connected state is in a white list; and
transmitting an alert if the traffic is not in the white list and if the context determined for the device indicates that the context does not correlate with the traffic.
1 Assignment
0 Petitions
Accused Products
Abstract
A system for malware and anomaly detection via activity recognition based on sensor is disclosed. The system may analyze sensor data collected during a selected time period from one or more sensors that are associated with a device. Once the sensor data is analyzed, the system may determine a context of the device when the device is in a connected state. The system may determine the context of the device based on the sensor data collected during the selected time period. The system may also determine if traffic received or transmitted by the device during the connected state is in a white list. Furthermore, the system may transmit an alert if the traffic is determined to not be in the white list or if the context determined for the device indicates that the context does not correlate with the traffic.
40 Citations
20 Claims
-
1. A system for providing malware and anomaly detection via activity recognition based on sensor data, the system comprising:
-
a memory that stores instructions; a processor that executes the instructions to perform operations, the operations comprising; analyzing sensor data collected during a selected time period from at least one sensor associated with a device; determining a context of the device when the device is in a connected state, wherein the context of the device is determined based on the sensor data collected during the selected time period, wherein the context of the device comprises an indication as to a physical orientation of the device and a position of the device; determining if traffic received or transmitted by the device during the connected state is in a white list; and transmitting an alert if the traffic is not in the white list and if the context determined for the device indicates that the context does not correlate with the traffic. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9)
-
-
10. A method for providing malware and anomaly detection via activity recognition based on sensor data, the method comprising:
-
analyzing sensor data collected during a selected time period from at least one sensor associated with a device; determining, by utilizing instructions from memory that are executed by a processor, a context of the device when the device is in a connected state, wherein the context of the device is determined based on the sensor data collected during the selected time period, wherein the context of the device comprises an indication as to a physical orientation of the device and a position of the device; determining if traffic received or transmitted by the device during the connected state is in a white list; and transmitting an alert if the traffic is not in the white list and if the context determined for the device indicates that the context does not correlate with the traffic. - View Dependent Claims (11, 12, 13, 14, 15, 16, 17)
-
-
18. A computer-readable device comprising instructions, which when executed by a processor, cause the processor to perform operations comprising:
-
analyzing sensor data collected during a selected time period from at least one sensor associated with a device; determining a context of the device when the device is in a connected state, wherein the context of the device is determined based on the sensor data collected during the selected time period, wherein the context of the device comprises an indication as to a physical orientation of the device and a position of the device; determining if traffic received or transmitted by the device during the connected state is in a white list; and transmitting an alert if the traffic is not in the white list and if the context determined for the device indicates that the context does not correlate with the traffic. - View Dependent Claims (19, 20)
-
Specification