The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jan. 13, 2015

Filed:

Feb. 04, 2013
Applicant:

International Business Machines Corporation, Armonk, NY (US);

Inventors:

Mihai Christodorescu, Briarcliff Manor, NY (US);

Andrew Davidson, Madison, WI (US);

Reiner Sailer, Scarsdale, NY (US);

Wietse Venema, Yorktown Heights, NY (US);

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 11/00 (2006.01); G06F 21/56 (2013.01); G06F 21/52 (2013.01);
U.S. Cl.
CPC ...
G06F 21/56 (2013.01); G06F 21/52 (2013.01);
Abstract

Access is obtained to a plurality of information flow theories for a plurality of malicious programs. The information flow theories include differences in information flows between the malicious programs, executing in a controlled environment, and information flows of known benign programs. Execution of a suspicious program is monitored by comparing runtime behavior of the suspicious program to the plurality of information flow theories. An alarm is output if the runtime behavior of the suspicious program matches at least one of the plurality of information flow theories.


Find Patent Forward Citations

Loading…