首页> 外国专利> Method and system for real-time tamper evidence gathering for software

Method and system for real-time tamper evidence gathering for software

机译:用于软件的实时篡改证据收集的方法和系统

摘要

A method and system are directed to differentiating between normal characteristics and abnormal characteristics within a software process, such that tampering of the software process may be identified programmatically. The identification of behavior that may be defined as normal may vary. Such behavior may include a sequence of selected system level calls that may access resources considered relevant, and the like. Data on the selected behavior is gathered, and when a sufficient amount of abnormal behavior has been detected, a signal may be provided such that an action may be performed. Samples of the gathered data are assigned a unique value. Statistical information is determined from the collected behavior, including trend data. Such trend data is compared to trends identified as normal for the software process, and a determination is made whether the sampled behavior is non-normal.
机译:一种方法和系统旨在在软件过程中区分正常特征和异常特征,从而可以以编程方式识别对软件过程的篡改。可以定义为正常行为的标识可能会有所不同。这样的行为可以包括可以访问被认为相关的资源等的一系列选定的系统级调用。收集关于所选行为的数据,并且当已经检测到足够数量的异常行为时,可以提供信号以使得可以执行动作。收集的数据样本将分配一个唯一值。根据收集的行为(包括趋势数据)确定统计信息。将这种趋势数据与确定为软件过程正常的趋势进行比较,然后确定采样行为是否为非正常行为。

著录项

  • 公开/公告号US7594271B2

    专利类型

  • 公开/公告日2009-09-22

    原文格式PDF

  • 申请/专利权人 OSCAR V. ZHUK;VINCE M. ROHR;

    申请/专利号US20030668046

  • 发明设计人 VINCE M. ROHR;OSCAR V. ZHUK;

    申请日2003-09-22

  • 分类号G06F21/00;

  • 国家 US

  • 入库时间 2022-08-21 19:31:43

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号