The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Aug. 29, 2023

Filed:

Aug. 10, 2021
Applicant:

Nec Laboratories America, Inc., Princeton, NJ (US);

Inventors:

Xiao Yu, Princeton, NJ (US);

Haifeng Chen, West Windsor, NJ (US);

Fei Zuo, Columbia, SC (US);

Assignee:
Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/52 (2013.01); G06F 16/2458 (2019.01); G06N 5/022 (2023.01); G06F 21/55 (2013.01); G06F 9/54 (2006.01);
U.S. Cl.
CPC ...
G06F 21/52 (2013.01); G06F 9/547 (2013.01); G06F 16/2465 (2019.01); G06F 21/55 (2013.01); G06N 5/022 (2013.01); G06F 2221/033 (2013.01);
Abstract

A computer-implemented method is provided for computer intrusion detection. The method includes establishing a mapping from low-level system calls to user functions in computer programs. The user functions run in a user space of an operating system. The method further includes identifying, using a search algorithm inputting the mapping and a system-call trace captured at runtime, any of the user functions that trigger the low-level system calls in the system-call trace. The method further includes performing, by a processor device, intrusion detection responsive to a provenance graph with program contexts. The provenance graph has nodes formed from the user functions that trigger the low-level system calls in the system-call trace. Edges in the provenance graph have edge labels describing high-level system operations for low-level system call to high-level system operation correlation-based intrusion detection.


Find Patent Forward Citations

Loading…